CVE-2022-20740
published 2022-05-03CVE-2022-20740: A vulnerability in the web-based management interface of Cisco Firepower Management Center (FMC) Software could allow an unauthenticated, remote attacker to…
PriorityP427medium6.1CVSS 3.1
AVNACLPRNUIRSCCLILAN
EPSS
0.70%
49.0th percentile
A vulnerability in the web-based management interface of Cisco Firepower Management Center (FMC) Software could allow an unauthenticated, remote attacker to conduct a cross-site scripting attack. This vulnerability is due to improper validation of user-supplied input to the web-based management interface. An attacker could exploit this vulnerability by convincing a user to click a link designed to pass malicious input to the interface. A successful exploit could allow the attacker to conduct cross-site scripting attacks and gain access to sensitive browser-based information.
Affected
5 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | cisco_firepower_management_center_6.1.0 | — | — |
| cisco | firepower_management_center | — | — |
| cisco | secure_firewall_management_center | < 6.6.5.2 | 6.6.5.2 |
| cisco | secure_firewall_management_center | >= 6.7.0 < 7.0.2 | 7.0.2 |
| cisco | secure_firewall_management_center | >= 7.1.0 < 7.1.0.1 | 7.1.0.1 |
CVSS provenance
nvdv3.16.1MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
vendor_cisco6.1MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Cisco
Cisco Firepower Management Center Software Cross-Site Scripting Vulnerability
vendor_cisco·2022-04-27·CVSS 6.1
CVE-2022-20740 [MEDIUM] CWE-80 Cisco Firepower Management Center Software Cross-Site Scripting Vulnerability
Cisco Firepower Management Center Software Cross-Site Scripting Vulnerability
A vulnerability in the web-based management interface of Cisco Firepower Management Center (FMC) Software could allow an unauthenticated, remote attacker to conduct a cross-site scripting attack.
This vulnerability is due to improper validation of user-supplied input to the web-based management interface. An attacker could exploit this vulnerability by convincing a user to click a link designed to pass malicious input to the interface. A successful exploit could allow the attacker to conduct cross-site scripting attacks and gain access to sensitive browser-based information.
Cisco has released software updates that address these vulnerabilities. There are no workarounds that address these vulnerabilities.
This
Cisco
Cisco Firepower Management Center Software Cross-Site Scripting Vulnerability
vendor_cisco·CVSS 3.1
CVE-2022-20740 Cisco Firepower Management Center Software Cross-Site Scripting Vulnerability
CVE-2022-20740: Cisco Firepower Management Center Software Cross-Site Scripting Vulnerability
A vulnerability in the web-based management interface of Cisco Firepower Management Center (FMC) Software could allow an unauthenticated, remote attacker to conduct a cross-site scripting attack. This vulnerability is due to improper validation of user-supplied input to the web-based management interface. An attacker could exploit this vulnerability by convincing a user to click a link designed to pass malicious input to the interface. A successful exploit could allow the attacker to conduct cross-site scripting attacks and gain access to sensitive browser-based information. Cisco has released software updates that address these vulnerabilities. There are no
CVSS: 3.1
CWE: CWE-80, CWE-80
Bug IDs:
GHSA
GHSA-39fq-5jf8-4787: A vulnerability in the web-based management interface of Cisco Firepower Management Center (FMC) Software could allow an unauthenticated, remote attac
ghsa_unreviewed·2022-05-04
CVE-2022-20740 [MEDIUM] CWE-79 GHSA-39fq-5jf8-4787: A vulnerability in the web-based management interface of Cisco Firepower Management Center (FMC) Software could allow an unauthenticated, remote attac
A vulnerability in the web-based management interface of Cisco Firepower Management Center (FMC) Software could allow an unauthenticated, remote attacker to conduct a cross-site scripting attack. This vulnerability is due to improper validation of user-supplied input to the web-based management interface. An attacker could exploit this vulnerability by convincing a user to click a link designed to pass malicious input to the interface. A successful exploit could allow the attacker to conduct cross-site scripting attacks and gain access to sensitive browser-based information.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2022-05-03
Published