VendorsCiscosecure_firewall_management_centerall versions
Vulnerabilities

Cisco Secure Firewall Management Center

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

187CVEs
CVE-2024-20471
A vulnerability in the web-based management interface of Cisco Secure Firewall Management Center (FMC) Software could allow an authenticated, remote attacker to conduct SQL injection attacks on an affected system. This vulnerability exists because the web-based management interface does not validate user input adequately. An attacker could exploit this vulnerability by authenticating to the application as an Administrator and sending crafted SQL queries to an affected system. A successful exploit could allow the attacker to obtain unauthorized data from the database and make changes to the system. To exploit this vulnerability, an attacker would need Administrator-level privileges.
Published 2024-10-23 · Analyzed
6.5EPSS 0.004
CVE-2024-20473
A vulnerability in the web-based management interface of Cisco Secure Firewall Management Center (FMC) Software could allow an authenticated, remote attacker to conduct SQL injection attacks on an affected system. This vulnerability exists because the web-based management interface does not validate user input adequately. An attacker could exploit this vulnerability by authenticating to the application as an Administrator and sending crafted SQL queries to an affected system. A successful exploit could allow the attacker to obtain unauthorized data from the database and make changes to the system. To exploit this vulnerability, an attacker would need Administrator-level privileges.
Published 2024-10-23 · Analyzed
6.5EPSS 0.004
CVE-2024-20472
A vulnerability in the web-based management interface of Cisco Secure Firewall Management Center (FMC) Software could allow an authenticated, remote attacker to conduct SQL injection attacks on an affected system. This vulnerability exists because the web-based management interface does not validate user input adequately. An attacker could exploit this vulnerability by authenticating to the application as an Administrator and sending crafted SQL queries to an affected system. A successful exploit could allow the attacker to obtain unauthorized data from the database and make changes to the system. To exploit this vulnerability, an attacker would need Administrator-level privileges.
Published 2024-10-23 · Analyzed
6.5EPSS 0.004
CVE-2025-20301
Cisco Secure Firewall Management Center Software Authorization Bypass Vulnerability
Published 2025-08-14 · Analyzed
6.5EPSS 0.004
CVE-2019-1642
Cisco Firepower Management Center Cross-Site Scripting Vulnerability
Published 2019-01-23 · Modified
6.11 PoCEPSS 0.039
CVE-2019-1671
Cisco Firepower Management Center Cross-Site Scripting Vulnerability
Published 2019-02-07 · Modified
6.1EPSS 0.012
CVE-2019-1930
Cisco Firepower Management Center RSS Cross-Site Scripting Vulnerabilities
Published 2019-07-06 · Modified
6.1EPSS 0.011
CVE-2019-1931
Cisco Firepower Management Center RSS Cross-Site Scripting Vulnerabilities
Published 2019-07-06 · Modified
6.1EPSS 0.011
CVE-2017-12220
A vulnerability in the web-based management interface of Cisco Firepower Management Center could allow an unauthenticated, remote attacker to conduct a reflected cross-site scripting (XSS) attack against a user of the web-based management interface of an affected device. The vulnerability is due to insufficient validation of user-supplied input by the web-based management interface of an affected device. An attacker could exploit this vulnerability by persuading a user of the interface to click a crafted link. A successful exploit could allow the attacker to execute arbitrary script code in the context of the interface or allow the attacker to access sensitive browser-based information. Cisco Bug IDs: CSCvc50771.
Published 2017-09-07 · Modified
6.1EPSS 0.009
CVE-2016-6365
Cross-site scripting (XSS) vulnerability in Cisco Firepower Management Center 4.10.3, 5.2.0, 5.3.0, 5.3.0.2, 5.3.1, and 5.4.0 allows remote attackers to inject arbitrary web script or HTML via unspecified parameters, aka Bug IDs CSCur25508 and CSCur25518.
Published 2016-08-23 · Modified
6.1EPSS 0.009
CVE-2020-3311
Cisco Firepower Management Center Open Redirect Vulnerability
Published 2020-05-06 · Modified
6.1EPSS 0.008
CVE-2020-3558
Cisco Firepower Management Center Software Open Redirect Vulnerability
Published 2020-10-21 · Modified
6.1EPSS 0.008
CVE-2020-3515
Cisco Firepower Management Center Software Cross-Site Scripting Vulnerabilities
Published 2020-10-21 · Modified
6.1EPSS 0.008
CVE-2020-3553
Cisco Firepower Management Center Software Cross-Site Scripting Vulnerabilities
Published 2020-10-21 · Modified
6.1EPSS 0.008
CVE-2016-1431
Cross-site scripting (XSS) vulnerability in Cisco Firepower Management Center 4.10.3, 5.2.0, 5.3.0, 5.3.1, and 5.4.0 allows remote attackers to inject arbitrary web script or HTML via a crafted URL, aka Bug ID CSCur25516.
Published 2016-06-18 · Modified
6.1EPSS 0.008
CVE-2022-20740
Cisco Firepower Management Center Software Cross-Site Scripting Vulnerability
Published 2022-05-03 · Modified
6.1EPSS 0.008
CVE-2024-20275
Cisco Secure Firewall Management Center Software Backup Cluster Command Injection Vulnerability
Published 2024-10-23 · Analyzed
6.1EPSS 0.005
CVE-2024-20273
Cisco Firepower Management Center Software Cross-Site Scripting Vulnerability
Published 2024-10-23 · Analyzed
6.1EPSS 0.004
CVE-2023-20206
Multiple vulnerabilities in the web-based management interface of Cisco Firepower Management Center (FMC) Software could allow an unauthenticated, remote attacker to conduct a stored cross-site scripting (XSS) attack against a user of the interface of an affected device. These vulnerabilities are due to insufficient validation of user-supplied input by the web-based management interface. An attacker could exploit these vulnerabilities by inserting crafted input into various data fields in an affected interface. A successful exploit could allow the attacker to execute arbitrary script code in the context of the interface, or access sensitive, browser-based information. In some cases, it is also possible to cause a temporary availability impact to portions of the FMC Dashboard.
Published 2023-11-01 · Modified
6.1EPSS 0.004
CVE-2023-20005
Multiple vulnerabilities in the web-based management interface of Cisco Firepower Management Center (FMC) Software could allow an unauthenticated, remote attacker to conduct a stored cross-site scripting (XSS) attack against a user of the interface of an affected device. These vulnerabilities are due to insufficient validation of user-supplied input by the web-based management interface. An attacker could exploit these vulnerabilities by inserting crafted input into various data fields in an affected interface. A successful exploit could allow the attacker to execute arbitrary script code in the context of the interface, or access sensitive, browser-based information. In some cases, it is also possible to cause a temporary availability impact to portions of the FMC Dashboard.
Published 2023-11-01 · Modified
6.1EPSS 0.004
CVE-2023-20074
Multiple vulnerabilities in the web-based management interface of Cisco Firepower Management Center (FMC) Software could allow an unauthenticated, remote attacker to conduct a stored cross-site scripting (XSS) attack against a user of the interface of an affected device. These vulnerabilities are due to insufficient validation of user-supplied input by the web-based management interface. An attacker could exploit these vulnerabilities by inserting crafted input into various data fields in an affected interface. A successful exploit could allow the attacker to execute arbitrary script code in the context of the interface, or access sensitive, browser-based information. In some cases, it is also possible to cause a temporary availability impact to portions of the FMC Dashboard.
Published 2023-11-01 · Modified
6.1EPSS 0.004
CVE-2023-20041
Multiple vulnerabilities in the web-based management interface of Cisco Firepower Management Center (FMC) Software could allow an unauthenticated, remote attacker to conduct a stored cross-site scripting (XSS) attack against a user of the interface of an affected device. These vulnerabilities are due to insufficient validation of user-supplied input by the web-based management interface. An attacker could exploit these vulnerabilities by inserting crafted input into various data fields in an affected interface. A successful exploit could allow the attacker to execute arbitrary script code in the context of the interface, or access sensitive, browser-based information. In some cases, it is also possible to cause a temporary availability impact to portions of the FMC Dashboard.
Published 2023-11-01 · Modified
6.1EPSS 0.004
CVE-2024-20372
A vulnerability in the web-based management interface of Cisco Firepower Management Center (FMC) Software could allow an unauthenticated, remote attacker to conduct a stored cross-site scripting (XSS) attack against a user of the interface of an affected device. This vulnerability is due to insufficient validation of user-supplied input by the web-based management interface. An attacker could exploit this vulnerability by inserting crafted input into various data fields in an affected interface. A successful exploit could allow the attacker to execute arbitrary script code in the context of the interface, or access sensitive, browser-based information.
Published 2024-10-23 · Analyzed
6.1EPSS 0.004
CVE-2024-20386
A vulnerability in the web-based management interface of Cisco Firepower Management Center (FMC) Software could allow an unauthenticated, remote attacker to conduct a stored cross-site scripting (XSS) attack against a user of the interface of an affected device. This vulnerability is due to insufficient validation of user-supplied input by the web-based management interface. An attacker could exploit this vulnerability by inserting crafted input into various data fields in an affected interface. A successful exploit could allow the attacker to execute arbitrary script code in the context of the interface, or access sensitive, browser-based information.
Published 2024-10-23 · Analyzed
6.1EPSS 0.004
CVE-2024-20409
A vulnerability in the web-based management interface of Cisco Firepower Management Center (FMC) Software could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface of an affected device. This vulnerability is due to insufficient validation of user-supplied input by the web-based management interface. An attacker could exploit this vulnerability by inserting crafted input into various data fields in an affected interface. A successful exploit could allow the attacker to execute arbitrary script code in the context of the interface, or access sensitive, browser-based information.
Published 2024-10-23 · Analyzed
6.1EPSS 0.003
CVE-2024-20410
A vulnerability in the web-based management interface of Cisco Firepower Management Center (FMC) Software could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface of an affected device. This vulnerability is due to insufficient validation of user-supplied input by the web-based management interface. An attacker could exploit this vulnerability by inserting crafted input into various data fields in an affected interface. A successful exploit could allow the attacker to execute arbitrary script code in the context of the interface, or access sensitive, browser-based information.
Published 2024-10-23 · Analyzed
6.1EPSS 0.003
CVE-2024-20415
A vulnerability in the web-based management interface of Cisco Firepower Management Center (FMC) Software could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface of an affected device. This vulnerability is due to insufficient validation of user-supplied input by the web-based management interface. An attacker could exploit this vulnerability by inserting crafted input into various data fields in an affected interface. A successful exploit could allow the attacker to execute arbitrary script code in the context of the interface, or access sensitive, browser-based information.
Published 2024-10-23 · Analyzed
6.1EPSS 0.003
CVE-2025-20235
Cisco Secure Firewall Management Center Software Cross-Site Scripting Vulnerability
Published 2025-08-14 · Analyzed
6.1EPSS 0.003
CVE-2026-20044
Cisco Secure Firewall Management Center Command Injection Vulnerability
Published 2026-03-04 · Analyzed
6.0EPSS 0.001
CVE-2019-1978
Cisco Firepower Threat Defense Software Stream Reassembly Bypass Vulnerability
Published 2019-11-05 · Modified
5.81 PoCEPSS 0.094
CVE-2018-0384
A vulnerability in the detection engine of Cisco FireSIGHT System Software could allow an unauthenticated, remote attacker to bypass a URL-based access control policy that is configured to block traffic for an affected system. The vulnerability exists because the affected software incorrectly handles TCP packets that are received out of order when a TCP SYN retransmission is issued. An attacker could exploit this vulnerability by sending a maliciously crafted connection through an affected device. A successful exploit could allow the attacker to bypass a URL-based access control policy that is configured to block traffic for the affected system. Cisco Bug IDs: CSCvh84511.
Published 2018-07-16 · Modified
5.8EPSS 0.025
CVE-2020-3315
Multiple Cisco Products Snort HTTP Detection Engine File Policy Bypass Vulnerability
Published 2020-05-06 · Modified
5.8EPSS 0.022
CVE-2017-3809
A vulnerability in the Policy deployment module of the Cisco Firepower Management Center (FMC) could allow an unauthenticated, remote attacker to prevent deployment of a complete and accurate rule base. More Information: CSCvb95281. Known Affected Releases: 6.1.0 6.2.0. Known Fixed Releases: 6.1.0.1 6.2.0.
Published 2017-02-03 · Modified
5.8EPSS 0.022
CVE-2021-1224
Multiple Cisco Products Snort TCP Fast Open File Policy Bypass Vulnerability
Published 2021-01-13 · Modified
5.8EPSS 0.020
CVE-2018-0333
A vulnerability in the VPN configuration management of Cisco FireSIGHT System Software could allow an unauthenticated, remote attacker to bypass VPN security due to unintended side effects of dynamic configuration changes that could allow an attacker to bypass configured policies. The vulnerability is due to incorrect management of the configured interface names and VPN parameters when dynamic CLI configuration changes are performed. An attacker could exploit this vulnerability by sending packets through an interface on the targeted device. A successful exploit could allow the attacker to bypass configured VPN policies. Cisco Bug IDs: CSCvh49388.
Published 2018-06-07 · Modified
5.8EPSS 0.019
CVE-2017-3814
A vulnerability in Cisco Firepower System Software could allow an unauthenticated, remote attacker to maliciously bypass the appliance's ability to block certain web content, aka a URL Bypass. More Information: CSCvb93980. Known Affected Releases: 5.3.0 5.4.0 6.0.0 6.0.1 6.1.0.
Published 2017-02-03 · Modified
5.8EPSS 0.019
CVE-2019-1833
Cisco Firepower Threat Defense Software SSL/TLS Policy Bypass Vulnerability
Published 2019-05-16 · Modified
5.8EPSS 0.017
CVE-2017-12300
A vulnerability in the SNORT detection engine of Cisco Firepower System Software could allow an unauthenticated, remote attacker to bypass a file policy that is configured to block the Server Message Block Version 2 (SMB2) protocol. The vulnerability is due to the incorrect detection of an SMB2 file when the detection is based on the length of the file. An attacker could exploit this vulnerability by sending a crafted SMB2 transfer request through the targeted device. A successful exploit could allow the attacker to bypass filters that are configured to block SMB2 traffic. Cisco Bug IDs: CSCve58398.
Published 2017-11-16 · Modified
5.8EPSS 0.016
CVE-2019-12701
Cisco Firepower Management Center Software File and Malware Policy Bypass Vulnerability
Published 2019-10-02 · Modified
5.8EPSS 0.015
CVE-2018-0281
A vulnerability in the detection engine of Cisco Firepower System Software could allow an unauthenticated, remote attacker to restart an instance of the Snort detection engine on an affected device, resulting in a brief denial of service (DoS) condition. The vulnerability is due to the incorrect handling of a Transport Layer Security (TLS) extension during TLS connection setup for the affected software. An attacker could exploit this vulnerability by sending a crafted TLS connection setup request to an affected device. A successful exploit could allow the attacker to cause the Snort detection engine on the affected device to restart, resulting in a DoS condition. Cisco Bug IDs: CSCvg97808.
Published 2018-05-02 · Modified
5.8EPSS 0.014
← Prev3 / 5Next →