VendorsCiscosecure_firewall_management_centerany version
Vulnerabilities

Cisco Secure Firewall Management Center any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

57CVEs
CVE-2019-16028
Cisco Firepower Management Center Lightweight Directory Access Protocol Authentication Bypass Vulnerability
Published 2020-09-23 · Modified
10.0EPSS 0.034
CVE-2023-20048
A vulnerability in the web services interface of Cisco Firepower Management Center (FMC) Software could allow an authenticated, remote attacker to execute certain unauthorized configuration commands on a Firepower Threat Defense (FTD) device that is managed by the FMC Software. This vulnerability is due to insufficient authorization of configuration commands that are sent through the web service interface. An attacker could exploit this vulnerability by authenticating to the FMC web services interface and sending a crafted HTTP request to an affected device. A successful exploit could allow the attacker to execute certain configuration commands on the targeted FTD device. To successfully exploit this vulnerability, an attacker would need valid credentials on the FMC Software.
Published 2023-11-01 · Modified
9.9EPSS 0.158
CVE-2019-15992
Cisco Adaptive Security Appliance Software and Firepower Threat Defense Software Remote Code Execution Vulnerability
Published 2020-09-23 · Modified
9.0EPSS 0.041
CVE-2022-20743
Cisco Firepower Management Center File Upload Security Bypass Vulnerability
Published 2022-05-03 · Modified
9.0EPSS 0.040
CVE-2019-12690
Cisco Firepower Management Center Command Injection Vulnerability
Published 2019-10-02 · Modified
9.0EPSS 0.035
CVE-2019-12689
Cisco Firepower Management Center Remote Code Execution Vulnerability
Published 2019-10-02 · Modified
9.0EPSS 0.031
CVE-2023-20220
Multiple vulnerabilities in the web-based management interface of Cisco Firepower Management Center (FMC) Software could allow an authenticated, remote attacker to execute arbitrary commands on the underlying operating system. To exploit these vulnerabilities, the attacker must have valid device credentials, but does not need Administrator privileges. These vulnerabilities are due to insufficient validation of user-supplied input for certain configuration options. An attacker could exploit these vulnerabilities by using crafted input within the device configuration GUI. A successful exploit could allow the attacker to execute arbitrary commands on the device, including on the underlying operating system, which could also affect the availability of the device.
Published 2023-11-01 · Modified
8.8EPSS 0.011
CVE-2023-20219
Multiple vulnerabilities in the web management interface of Cisco Firepower Management Center (FMC) Software could allow an authenticated, remote attacker to execute arbitrary commands on the underlying operating system. The attacker would need valid device credentials but does not require administrator privileges to exploit this vulnerability. These vulnerabilities are due to insufficient validation of user-supplied input for certain configuration options. An attacker could exploit these vulnerabilities by using crafted input within the device configuration GUI. A successful exploit could allow the attacker to execute arbitrary commands on the device including the underlying operating system which could also affect the availability of the device.
Published 2023-11-01 · Modified
8.8EPSS 0.009
CVE-2020-3302
Cisco Firepower Management Center File Overwrite Vulnerability
Published 2020-05-06 · Modified
8.5EPSS 0.017
CVE-2023-20063
Cisco Cisco Firepower Threat Defense Software and Cisco Firepower Management Center Code Injection Vulnerability
Published 2023-11-01 · Modified
8.2EPSS 0.004
CVE-2020-3514
Cisco Firepower Threat Defense Software Multi-Instance Container Escape Vulnerability
Published 2020-10-21 · Modified
8.2EPSS 0.004
CVE-2020-3550
Cisco Firepower Management Center Software and Firepower Threat Defense Software Directory Traversal Vulnerability
Published 2020-10-21 · Modified
8.1EPSS 0.022
CVE-2020-3549
Cisco Firepower Management Center Software and Firepower Threat Defense Software sftunnel Pass the Hash Vulnerability
Published 2020-10-21 · Modified
8.1EPSS 0.010
CVE-2026-20002
A vulnerability in the web-based management interface of Cisco Secure FMC Software could allow an authenticated, remote attacker to conduct SQL injection attacks on an affected system. This vulnerability is due to inadequate validation of user-supplied input. An attacker could exploit this vulnerability by sending crafted requests to an affected device. A successful exploit could allow the attacker to obtain full access to the database and read certain files on the underlying operating system. To exploit this vulnerability, the attacker would need valid user credentials.
Published 2026-03-04 · Analyzed
8.1EPSS 0.003
CVE-2019-1699
Cisco Firepower Threat Defense Software Command Injection Vulnerability
Published 2019-05-03 · Modified
7.8EPSS 0.007
CVE-2019-12700
Cisco FTD, FMC, and FXOS Software Pluggable Authentication Module Denial of Service Vulnerability
Published 2019-10-02 · Modified
7.7EPSS 0.019
CVE-2022-20854
A vulnerability in the processing of SSH connections of Cisco Firepower Management Center (FMC) and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to improper error handling when an SSH session fails to be established. An attacker could exploit this vulnerability by sending a high rate of crafted SSH connections to the instance. A successful exploit could allow the attacker to cause resource exhaustion, resulting in a reboot on the affected device.
Published 2022-11-10 · Modified
7.5EPSS 0.009
CVE-2022-20918
A vulnerability in the Simple Network Management Protocol (SNMP) access controls for Cisco FirePOWER Software for Adaptive Security Appliance (ASA) FirePOWER module, Cisco Firepower Management Center (FMC) Software, and Cisco Next-Generation Intrusion Prevention System (NGIPS) Software could allow an unauthenticated, remote attacker to perform an SNMP GET request using a default credential. This vulnerability is due to the presence of a default credential for SNMP version 1 (SNMPv1) and SNMP version 2 (SNMPv2). An attacker could exploit this vulnerability by sending an SNMPv1 or SNMPv2 GET request to an affected device. A successful exploit could allow the attacker to retrieve sensitive information from the device using the default credential. This attack will only be successful if SNMP is configured, and the attacker can only perform SNMP GET requests; write access using SNMP is not allowed.
Published 2022-11-10 · Modified
7.5EPSS 0.009
CVE-2023-20155
A vulnerability in a logging API in Cisco Firepower Management Center (FMC) Software could allow an unauthenticated, remote attacker to cause the device to become unresponsive or trigger an unexpected reload. This vulnerability could also allow an attacker with valid user credentials, but not Administrator privileges, to view a system log file that they would not normally have access to. This vulnerability is due to a lack of rate-limiting of requests that are sent to a specific API that is related to an FMC log. An attacker could exploit this vulnerability by sending a high rate of HTTP requests to the API. A successful exploit could allow the attacker to cause a denial of service (DoS) condition due to the FMC CPU spiking to 100 percent utilization or to the device reloading. CPU utilization would return to normal if the attack traffic was stopped before an unexpected reload was triggered.
Published 2023-11-01 · Modified
7.5EPSS 0.007
CVE-2022-20744
Cisco Firepower Management Center Software Information Disclosure Vulnerability
Published 2022-05-03 · Modified
6.5EPSS 0.009
CVE-2020-3313
Cisco Firepower Management Center Cross-Site Scripting Vulnerability
Published 2020-05-06 · Modified
6.5EPSS 0.008
CVE-2023-20114
A vulnerability in the file download feature of Cisco Firepower Management Center (FMC) Software could allow an authenticated, remote attacker to download arbitrary files from an affected system. This vulnerability is due to a lack of input sanitation. An attacker could exploit this vulnerability by sending a crafted HTTPS request. A successful exploit could allow the attacker to download arbitrary files from the affected system.
Published 2023-11-01 · Modified
6.5EPSS 0.005
CVE-2017-12220
A vulnerability in the web-based management interface of Cisco Firepower Management Center could allow an unauthenticated, remote attacker to conduct a reflected cross-site scripting (XSS) attack against a user of the web-based management interface of an affected device. The vulnerability is due to insufficient validation of user-supplied input by the web-based management interface of an affected device. An attacker could exploit this vulnerability by persuading a user of the interface to click a crafted link. A successful exploit could allow the attacker to execute arbitrary script code in the context of the interface or allow the attacker to access sensitive browser-based information. Cisco Bug IDs: CSCvc50771.
Published 2017-09-07 · Modified
6.1EPSS 0.009
CVE-2020-3311
Cisco Firepower Management Center Open Redirect Vulnerability
Published 2020-05-06 · Modified
6.1EPSS 0.008
CVE-2020-3558
Cisco Firepower Management Center Software Open Redirect Vulnerability
Published 2020-10-21 · Modified
6.1EPSS 0.008
CVE-2020-3553
Cisco Firepower Management Center Software Cross-Site Scripting Vulnerabilities
Published 2020-10-21 · Modified
6.1EPSS 0.008
CVE-2020-3515
Cisco Firepower Management Center Software Cross-Site Scripting Vulnerabilities
Published 2020-10-21 · Modified
6.1EPSS 0.008
CVE-2022-20740
Cisco Firepower Management Center Software Cross-Site Scripting Vulnerability
Published 2022-05-03 · Modified
6.1EPSS 0.008
CVE-2023-20206
Multiple vulnerabilities in the web-based management interface of Cisco Firepower Management Center (FMC) Software could allow an unauthenticated, remote attacker to conduct a stored cross-site scripting (XSS) attack against a user of the interface of an affected device. These vulnerabilities are due to insufficient validation of user-supplied input by the web-based management interface. An attacker could exploit these vulnerabilities by inserting crafted input into various data fields in an affected interface. A successful exploit could allow the attacker to execute arbitrary script code in the context of the interface, or access sensitive, browser-based information. In some cases, it is also possible to cause a temporary availability impact to portions of the FMC Dashboard.
Published 2023-11-01 · Modified
6.1EPSS 0.004
CVE-2023-20074
Multiple vulnerabilities in the web-based management interface of Cisco Firepower Management Center (FMC) Software could allow an unauthenticated, remote attacker to conduct a stored cross-site scripting (XSS) attack against a user of the interface of an affected device. These vulnerabilities are due to insufficient validation of user-supplied input by the web-based management interface. An attacker could exploit these vulnerabilities by inserting crafted input into various data fields in an affected interface. A successful exploit could allow the attacker to execute arbitrary script code in the context of the interface, or access sensitive, browser-based information. In some cases, it is also possible to cause a temporary availability impact to portions of the FMC Dashboard.
Published 2023-11-01 · Modified
6.1EPSS 0.004
CVE-2023-20005
Multiple vulnerabilities in the web-based management interface of Cisco Firepower Management Center (FMC) Software could allow an unauthenticated, remote attacker to conduct a stored cross-site scripting (XSS) attack against a user of the interface of an affected device. These vulnerabilities are due to insufficient validation of user-supplied input by the web-based management interface. An attacker could exploit these vulnerabilities by inserting crafted input into various data fields in an affected interface. A successful exploit could allow the attacker to execute arbitrary script code in the context of the interface, or access sensitive, browser-based information. In some cases, it is also possible to cause a temporary availability impact to portions of the FMC Dashboard.
Published 2023-11-01 · Modified
6.1EPSS 0.004
CVE-2026-20044
Cisco Secure Firewall Management Center Command Injection Vulnerability
Published 2026-03-04 · Analyzed
6.0EPSS 0.001
CVE-2019-1978
Cisco Firepower Threat Defense Software Stream Reassembly Bypass Vulnerability
Published 2019-11-05 · Modified
5.81 PoCEPSS 0.094
CVE-2019-12701
Cisco Firepower Management Center Software File and Malware Policy Bypass Vulnerability
Published 2019-10-02 · Modified
5.8EPSS 0.015
CVE-2019-1981
Cisco Firepower Threat Defense Software NULL Character Obfuscation Detection Bypass Vulnerability
Published 2019-11-05 · Modified
5.8EPSS 0.010
CVE-2019-1980
Cisco Firepower Threat Defense Software Nonstandard Protocol Detection Bypass Vulnerability
Published 2019-11-05 · Modified
5.8EPSS 0.010
CVE-2021-1126
Cisco Firepower Management Center Information Disclosure Vulnerability
Published 2021-01-13 · Modified
5.5EPSS 0.003
CVE-2017-12221
A vulnerability in the web framework of Cisco Firepower Management Center could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web interface of the affected software. The vulnerability is due to insufficient validation of user-supplied input by the affected software. Successful exploitation of this vulnerability could allow the attacker to execute arbitrary code in the context of the affected system. Cisco Bug IDs: CSCvc38983.
Published 2017-09-07 · Modified
5.4EPSS 0.011
CVE-2020-3320
Cisco Firepower Management Center Cross-Site Scripting Vulnerability
Published 2020-10-08 · Modified
5.4EPSS 0.006
CVE-2022-20627
Cisco Firepower Management Center Software Cross-Site Scripting Vulnerabilities
Published 2022-05-03 · Modified
5.4EPSS 0.006
1 / 2Next →