CVE-2019-16028
published 2020-09-23CVE-2019-16028: A vulnerability in the web-based management interface of Cisco Firepower Management Center (FMC) could allow an unauthenticated, remote attacker to bypass…
PriorityP270critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
3.35%
87.3th percentile
A vulnerability in the web-based management interface of Cisco Firepower Management Center (FMC) could allow an unauthenticated, remote attacker to bypass authentication and execute arbitrary actions with administrative privileges on an affected device. The vulnerability is due to improper handling of Lightweight Directory Access Protocol (LDAP) authentication responses from an external authentication server. An attacker could exploit this vulnerability by sending crafted HTTP requests to an affected device. A successful exploit could allow the attacker to gain administrative access to the web-based management interface of the affected device.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | cisco_firepower_management_center | — | — |
| cisco | firepower_management_center_lightweight_directory_access_protocol | — | — |
| cisco | secure_firewall_management_center | < 6.2.3.16 | 6.2.3.16 |
| cisco | secure_firewall_management_center | >= 6.3.0 < 6.3.0.6 | 6.3.0.6 |
| cisco | secure_firewall_management_center | >= 6.4.0 < 6.4.0.7 | 6.4.0.7 |
| cisco | secure_firewall_management_center | >= 6.5.0 < 6.5.0.2 | 6.5.0.2 |
Detection & IOCsextracted from sources · hover to see the quote
- →Exploit vector is crafted HTTP requests to the web-based management interface of Cisco FMC; monitor for unauthenticated HTTP requests that result in administrative access ↗
- →The vulnerability involves improper handling of LDAP authentication responses; monitor for anomalous LDAP response handling on FMC devices that results in authentication bypass ↗
- →Successful exploitation grants administrative privileges without authentication; alert on unexpected admin-level sessions originating from unauthenticated sources on FMC web UI ↗
- ·The vulnerability is only exploitable when the FMC is configured to use an external LDAP authentication server; deployments using local authentication are not affected ↗
- ·There are no workarounds available; patching is the only remediation path ↗
CVSS provenance
nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv3.09.8CRITICALCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.010.0CRITICALAV:N/AC:L/Au:N/C:C/I:C/A:C
vendor_cisco9.8CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-wgx9-9frm-4cgq: A vulnerability in the web-based management interface of Cisco Firepower Management Center (FMC) could allow an unauthenticated, remote attacker to by
ghsa_unreviewed·2022-05-24
CVE-2019-16028 [CRITICAL] CWE-287 GHSA-wgx9-9frm-4cgq: A vulnerability in the web-based management interface of Cisco Firepower Management Center (FMC) could allow an unauthenticated, remote attacker to by
A vulnerability in the web-based management interface of Cisco Firepower Management Center (FMC) could allow an unauthenticated, remote attacker to bypass authentication and execute arbitrary actions with administrative privileges on an affected device. The vulnerability is due to improper handling of Lightweight Directory Access Protocol (LDAP) authentication responses from an external authentication server. An attacker could exploit this vulnerability by sending crafted HTTP requests to an affected device. A successful exploit could allow the attacker to gain administrative access to the web-based management interface of the affected device.
Cisco
Cisco Firepower Management Center Lightweight Directory Access Protocol Authentication Bypass Vulnerability
vendor_cisco·2020-01-22·CVSS 9.8
CVE-2019-16028 [CRITICAL] CWE-287 Cisco Firepower Management Center Lightweight Directory Access Protocol Authentication Bypass Vulnerability
Cisco Firepower Management Center Lightweight Directory Access Protocol Authentication Bypass Vulnerability
A vulnerability in the web-based management interface of Cisco Firepower Management Center (FMC) could allow an unauthenticated, remote attacker to bypass authentication and execute arbitrary actions with administrative privileges on an affected device.
The vulnerability is due to improper handling of Lightweight Directory Access Protocol (LDAP) authentication responses from an external authentication server. An attacker could exploit this vulnerability by sending crafted HTTP requests to an affected device. A successful exploit could allow the attacker to gain administrative access to the web-based management interface of the affected device.
Cisco has released software updates tha
Cisco
Cisco Firepower Management Center Lightweight Directory Access Protocol Authentication Bypass Vulnerability
vendor_cisco·CVSS 3.0
CVE-2019-16028 Cisco Firepower Management Center Lightweight Directory Access Protocol Authentication Bypass Vulnerability
CVE-2019-16028: Cisco Firepower Management Center Lightweight Directory Access Protocol Authentication Bypass Vulnerability
A vulnerability in the web-based management interface of Cisco Firepower Management Center (FMC) could allow an unauthenticated, remote attacker to bypass authentication and execute arbitrary actions with administrative privileges on an affected device. The vulnerability is due to improper handling of Lightweight Directory Access Protocol (LDAP) authentication responses from an external authentication server. An attacker could exploit this vulnerability by sending crafted HTTP requests to an affected device. A successful exploit could allow the attacker to gain administrative access to the web-based management interface of the affected device. Cisco has released softw
No detection rules found.
No public exploits indexed.
2020-09-23
Published