CVE-2021-34751

CWE-3174 documents4 sources
Severity
4.3MEDIUM
EPSS
0.2%
top 59.00%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedNov 15

Description

A vulnerability in the administrative web-based GUI configuration manager of Cisco Firepower Management Center (FMC) Software could allow an authenticated, remote attacker to access sensitive configuration information. The attacker would require low privilege credentials on an affected device. This vulnerability exists because of improper encryption of sensitive information stored within the GUI configuration manager. An attacker could exploit this vulnerability by logging into the GUI of Cisco

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:NExploitability: 2.8 | Impact: 1.4

Affected Packages2 packages

🔴Vulnerability Details

2
CVEList
Cisco Firepower Management Center Software Configuration Information Disclosure Vulnerability2024-11-15
GHSA
GHSA-95xp-3pj7-m5fh: A vulnerability in the administrative web-based GUI configuration manager of Cisco Firepower Management Center (FMC) Software could allow an authentic2024-11-15

📋Vendor Advisories

1
Cisco
Cisco Firepower Management Center Software Configuration Information Disclosure Vulnerabilities2021-10-27
CVE-2021-34751 (MEDIUM CVSS 4.3) | A vulnerability in the administrati | cvebase.io