VendorsCiscosecure_firewall_management_centerall versions
Vulnerabilities

Cisco Secure Firewall Management Center

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

187CVEs
CVE-2018-0283
A vulnerability in the detection engine of Cisco Firepower System Software could allow an unauthenticated, remote attacker to restart an instance of the Snort detection engine on an affected device, resulting in a brief denial of service (DoS) condition. The vulnerability is due to the incorrect handling of Transport Layer Security (TLS) TCP connection setup for the affected software. An attacker could exploit this vulnerability by sending crafted TLS traffic to an affected device. A successful exploit could allow the attacker to cause the Snort detection engine on the affected device to restart, resulting in a DoS condition. Cisco Bug IDs: CSCvg99327.
Published 2018-05-02 · Modified
5.8EPSS 0.014
CVE-2019-1981
Cisco Firepower Threat Defense Software NULL Character Obfuscation Detection Bypass Vulnerability
Published 2019-11-05 · Modified
5.8EPSS 0.010
CVE-2019-1982
Cisco Firepower Threat Defense Software HTTP Filtering Bypass Vulnerability
Published 2019-11-05 · Modified
5.8EPSS 0.010
CVE-2019-1980
Cisco Firepower Threat Defense Software Nonstandard Protocol Detection Bypass Vulnerability
Published 2019-11-05 · Modified
5.8EPSS 0.010
CVE-2024-20361
A vulnerability in the Object Groups for Access Control Lists (ACLs) feature of Cisco Firepower Management Center (FMC) Software could allow an unauthenticated, remote attacker to bypass configured access controls on managed devices that are running Cisco Firepower Threat Defense (FTD) Software. This vulnerability is due to the incorrect deployment of the Object Groups for ACLs feature from Cisco FMC Software to managed FTD devices in high-availability setups. After an affected device is rebooted following Object Groups for ACLs deployment, an attacker can exploit this vulnerability by sending traffic through the affected device. A successful exploit could allow the attacker to bypass configured access controls and successfully send traffic to devices that are expected to be protected by the affected device.
Published 2024-05-22 · Analyzed
5.8EPSS 0.004
CVE-2024-20274
Cisco Secure Firewall Management Center HTML Injection Vulnerability
Published 2024-10-23 · Analyzed
5.5EPSS 0.004
CVE-2021-1126
Cisco Firepower Management Center Information Disclosure Vulnerability
Published 2021-01-13 · Modified
5.5EPSS 0.003
CVE-2017-12221
A vulnerability in the web framework of Cisco Firepower Management Center could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web interface of the affected software. The vulnerability is due to insufficient validation of user-supplied input by the affected software. Successful exploitation of this vulnerability could allow the attacker to execute arbitrary code in the context of the affected system. Cisco Bug IDs: CSCvc38983.
Published 2017-09-07 · Modified
5.4EPSS 0.011
CVE-2017-6715
A vulnerability in the web framework of Cisco Firepower Management Center could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web interface. Affected Products: Cisco Firepower Management Center Releases 5.4.1.x and prior. More Information: CSCuy88951. Known Affected Releases: 5.4.1.6.
Published 2017-07-04 · Modified
5.4EPSS 0.006
CVE-2017-6717
A vulnerability in the web framework of Cisco Firepower Management Center could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web interface. More Information: CSCvc38801. Known Affected Releases: 6.0.1.3 6.2.1. Known Fixed Releases: 6.2.1.
Published 2017-07-04 · Modified
5.4EPSS 0.006
CVE-2017-6716
A vulnerability in the web framework code of Cisco Firepower Management Center could allow an authenticated, remote attacker to conduct a stored cross-site scripting (XSS) attack against a user of the web interface of an affected system. Affected Products: Cisco Firepower Management Center Software Releases prior to 6.0.0.0. More Information: CSCuy88785. Known Affected Releases: 5.4.1.6.
Published 2017-07-04 · Modified
5.4EPSS 0.006
CVE-2020-3320
Cisco Firepower Management Center Cross-Site Scripting Vulnerability
Published 2020-10-08 · Modified
5.4EPSS 0.006
CVE-2017-3847
A vulnerability in the web framework of Cisco Firepower Management Center could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web interface. More Information: CSCvc72741. Known Affected Releases: 6.2.1.
Published 2017-02-22 · Modified
5.4EPSS 0.006
CVE-2022-20627
Cisco Firepower Management Center Software Cross-Site Scripting Vulnerabilities
Published 2022-05-03 · Modified
5.4EPSS 0.006
CVE-2022-20628
Cisco Firepower Management Center Software Cross-Site Scripting Vulnerabilities
Published 2022-05-03 · Modified
5.4EPSS 0.006
CVE-2022-20629
Cisco Firepower Management Center Software Cross-Site Scripting Vulnerabilities
Published 2022-05-03 · Modified
5.4EPSS 0.006
CVE-2024-20269
Cisco Firepower Management Center Software Cross-Site Scripting Vulnerability
Published 2024-10-23 · Analyzed
5.4EPSS 0.004
CVE-2024-20300
Cisco Firepower Management Center Software Cross-Site Scripting Vulnerability
Published 2024-10-23 · Analyzed
5.4EPSS 0.004
CVE-2024-20264
Cisco Firepower Management Center Software Cross-Site Scripting Vulnerability
Published 2024-10-23 · Analyzed
5.4EPSS 0.004
CVE-2024-20298
Cisco Firepower Management Center Software Cross-Site Scripting Vulnerability
Published 2024-10-23 · Analyzed
5.4EPSS 0.004
CVE-2024-20377
A vulnerability in the web-based management interface of Cisco Firepower Management Center (FMC) could allow an authenticated, remote attacker to conduct a stored cross-site scripting (XSS) attack against a user of the interface. This vulnerability is due to the web-based management interface not properly validating user-supplied input. An attacker could exploit this vulnerability by by persuading a user of the interface to click a crafted link. A successful exploit could allow the attacker to execute arbitrary script code in the context of the affected interface or access sensitive, browser-based information.
Published 2024-10-23 · Analyzed
5.4EPSS 0.004
CVE-2024-20364
A vulnerability in the web-based management interface of Cisco Firepower Management Center (FMC) Software could allow an authenticated, remote attacker to conduct a stored cross-site scripting (XSS) attack against a user of the interface of an affected device. This vulnerability is due to insufficient validation of user-supplied input by the web-based management interface. An attacker could exploit this vulnerability by inserting crafted input into various data fields in an affected interface. A successful exploit could allow the attacker to execute arbitrary script code in the context of the interface, or access sensitive, browser-based information.
Published 2024-10-23 · Analyzed
5.4EPSS 0.004
CVE-2024-20387
A vulnerability in the web-based management interface of Cisco FMC Software could allow an authenticated, remote attacker to store malicious content for use in XSS attacks. This vulnerability is due to improper input sanitization in the web-based management interface of Cisco FMC Software. An attacker could exploit this vulnerability by persuading a user to click a malicious link. A successful exploit could allow the attacker to conduct a stored XSS attack on an affected device.
Published 2024-10-23 · Analyzed
5.4EPSS 0.003
CVE-2024-20403
A vulnerability in the web-based management interface of Cisco Firepower Management Center (FMC) Software could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface of an affected device. This vulnerability is due to insufficient validation of user-supplied input by the web-based management interface. An attacker could exploit this vulnerability by inserting crafted input into various data fields in an affected interface. A successful exploit could allow the attacker to execute arbitrary script code in the context of the interface, or access sensitive, browser-based information.
Published 2024-10-23 · Analyzed
5.4EPSS 0.003
CVE-2026-20316
Cisco Secure Firewall Management Center Software Static Credential Vulnerability
Published 2026-07-29 · Analyzed
5.3KEVEPSS 0.351
CVE-2021-1236
Multiple Cisco Products Snort Application Detection Engine Policy Bypass Vulnerability
Published 2021-01-13 · Modified
5.3EPSS 0.021
CVE-2016-1342
The device login page in Cisco FirePOWER Management Center 5.3 through 6.0.0.1 allows remote attackers to obtain potentially sensitive software-version information by reading help files, aka Bug ID CSCuy36654.
Published 2016-02-26 · Modified
5.3EPSS 0.011
CVE-2020-3307
Cisco Firepower Management Center Arbitrary Log File Write Vulnerability
Published 2020-05-06 · Modified
5.3EPSS 0.010
CVE-2020-3557
Cisco Firepower Management Center Software Denial of Service Vulnerability
Published 2020-10-21 · Modified
5.3EPSS 0.007
CVE-2022-20941
A vulnerability in the web-based management interface of Cisco Firepower Management Center (FMC) Software could allow an unauthenticated, remote attacker to access sensitive information. This vulnerability is due to missing authorization for certain resources in the web-based management interface together with insufficient entropy in these resource names. An attacker could exploit this vulnerability by sending a series of HTTPS requests to an affected device to enumerate resources on the device. A successful exploit could allow the attacker to retrieve sensitive information from the device.
Published 2022-11-10 · Modified
5.3EPSS 0.007
CVE-2024-20388
A vulnerability in the password change feature of Cisco Firepower Management Center (FMC) software could allow an unauthenticated, remote attacker to determine valid user names on an affected device. This vulnerability is due to improper authentication of password update responses. An attacker could exploit this vulnerability by forcing a password reset on an affected device. A successful exploit could allow the attacker to determine valid user names in the unauthenticated response to a forced password reset.
Published 2024-10-23 · Analyzed
5.3EPSS 0.004
CVE-2015-6411
Cisco FirePOWER Management Center 5.4.1.3, 6.0.0, and 6.0.1 provides verbose responses to requests for help files, which allows remote attackers to obtain potentially sensitive version information by reading an unspecified field, aka Bug ID CSCux37061.
Published 2015-12-15 · Modified
5.0EPSS 0.012
CVE-2019-12691
Cisco Firepower Management Center Directory Traversal Vulnerability
Published 2019-10-02 · Modified
4.9EPSS 0.051
CVE-2020-3308
Cisco Firepower Threat Defense Software Signature Verification Bypass Vulnerability
Published 2020-05-06 · Modified
4.9EPSS 0.006
CVE-2025-20218
Cisco Secure Firepower Management Center Software XPATH Injection Vulnerability
Published 2025-08-14 · Analyzed
4.9EPSS 0.005
CVE-2025-20306
Cisco Secure Firewall Management Center Software Command Injection Vulnerability
Published 2025-08-14 · Analyzed
4.9EPSS 0.004
CVE-2026-20003
A vulnerability in the REST API of Cisco Secure FMC Software could allow an authenticated, remote attacker to conduct SQL injection attacks on an affected system. This vulnerability is due to inadequate validation of user-supplied input. An attacker could exploit this vulnerability by sending crafted requests to an affected device. A successful exploit could allow the attacker to obtain read access to the database and read certain files on the underlying operating system. To exploit this vulnerability, the attacker would need valid user credentials with any of the following roles: Administrator Security approver Intrusion admin Access admin Network admin
Published 2026-03-04 · Analyzed
4.9EPSS 0.003
CVE-2019-1802
Cisco Firepower Management Center Persistent Cross-Site Scripting Vulnerability
Published 2019-04-18 · Modified
4.8EPSS 0.009
CVE-2019-1949
Cisco Firepower Management Center Persistent Cross-Site Scripting Vulnerability
Published 2019-08-08 · Modified
4.8EPSS 0.008
CVE-2019-15280
Cisco Firepower Management Center Software Stored Cross-Site Scripting Vulnerability
Published 2019-10-16 · Modified
4.8EPSS 0.006
← Prev4 / 5Next →