CVE-2024-20360
published 2024-05-22CVE-2024-20360: A vulnerability in the web-based management interface of Cisco Firepower Management Center (FMC) Software could allow an authenticated, remote attacker to…
PriorityP262high8.8CVSS 3.1
AVNACLPRLUINSUCHIHAH
EPSS
0.84%
53.7th percentile
A vulnerability in the web-based management interface of Cisco Firepower Management Center (FMC) Software could allow an authenticated, remote attacker to conduct SQL injection attacks on an affected system. This vulnerability exists because the web-based management interface does not adequately validate user input. An attacker could exploit this vulnerability by authenticating to the application and sending crafted SQL queries to an affected system. A successful exploit could allow the attacker to obtain any data from the database, execute arbitrary commands on the underlying operating system, and elevate privileges to root. To exploit this vulnerability, an attacker would need at least Read Only user credentials.
Affected
55 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | cisco_firepower_management_center | — | — |
| cisco | cisco_firepower_management_center | — | — |
| cisco | cisco_firepower_management_center | — | — |
| cisco | cisco_firepower_management_center | — | — |
| cisco | cisco_firepower_management_center | — | — |
| cisco | cisco_firepower_management_center | — | — |
| cisco | cisco_firepower_management_center | — | — |
| cisco | cisco_firepower_management_center | — | — |
| cisco | cisco_firepower_management_center | — | — |
| cisco | cisco_firepower_management_center | — | — |
| cisco | cisco_firepower_management_center | — | — |
| cisco | cisco_firepower_management_center | — | — |
| cisco | cisco_firepower_management_center | — | — |
| cisco | cisco_firepower_management_center | — | — |
| cisco | cisco_firepower_management_center | — | — |
| cisco | cisco_firepower_management_center | — | — |
| cisco | cisco_firepower_management_center | — | — |
| cisco | cisco_firepower_management_center | — | — |
| cisco | cisco_firepower_management_center | — | — |
| cisco | cisco_firepower_management_center | — | — |
| cisco | cisco_firepower_management_center | — | — |
| cisco | cisco_firepower_management_center | — | — |
| cisco | cisco_firepower_management_center | — | — |
| cisco | cisco_firepower_management_center | — | — |
| cisco | cisco_firepower_management_center | — | — |
Detection & IOCsextracted from sources · hover to see the quote
- →Exploit requires at least Read Only user credentials authenticating to the Cisco FMC web-based management interface and sending crafted SQL queries ↗
- →Successful exploitation can result in OS command execution and privilege escalation to root — monitor FMC for unexpected OS-level process spawning from web service accounts ↗
- →Track Cisco internal Bug ID CSCwf92182 for patch and indicator updates related to this vulnerability ↗
- ·No workarounds are available; the only remediation is applying Cisco-released software updates ↗
- ·Exploitation requires authentication — at minimum Read Only credentials — meaning unauthenticated access alone is insufficient to trigger the vulnerability ↗
CVSS provenance
nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
vendor_cisco8.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Cisco
Cisco Firepower Management Center Software SQL Injection Vulnerability
vendor_cisco·2024-05-22·CVSS 8.8
CVE-2024-20360 [HIGH] CWE-89 Cisco Firepower Management Center Software SQL Injection Vulnerability
Cisco Firepower Management Center Software SQL Injection Vulnerability
A vulnerability in the web-based management interface of Cisco Firepower Management Center (FMC) Software could allow an authenticated, remote attacker to conduct SQL injection attacks on an affected system.
This vulnerability exists because the web-based management interface does not adequately validate user input. An attacker could exploit this vulnerability by authenticating to the application and sending crafted SQL queries to an affected system. A successful exploit could allow the attacker to obtain any data from the database, execute arbitrary commands on the underlying operating system, and elevate privileges to root. To exploit this vulnerability, an attacker would need at least Read Only user credentials.
C
Cisco
Cisco Firepower Management Center Software SQL Injection Vulnerability
vendor_cisco·CVSS 3.1
CVE-2024-20360 Cisco Firepower Management Center Software SQL Injection Vulnerability
CVE-2024-20360: Cisco Firepower Management Center Software SQL Injection Vulnerability
A vulnerability in the web-based management interface of Cisco Firepower Management Center (FMC) Software could allow an authenticated, remote attacker to conduct SQL injection attacks on an affected system. This vulnerability exists because the web-based management interface does not adequately validate user input. An attacker could exploit this vulnerability by authenticating to the application and sending crafted SQL queries to an affected system. A successful exploit could allow the attacker to obtain any data from the database, execute arbitrary commands on the underlying operating system, and elevate privileges to root . To exploit this vulnerability, an attacker would need at least Read Only user
GHSA
GHSA-6qgg-8c65-w4qp: A vulnerability in the web-based management interface of Cisco Firepower Management Center (FMC) Software could allow an authenticated, remote attacke
ghsa_unreviewed·2024-05-22
CVE-2024-20360 [HIGH] CWE-89 GHSA-6qgg-8c65-w4qp: A vulnerability in the web-based management interface of Cisco Firepower Management Center (FMC) Software could allow an authenticated, remote attacke
A vulnerability in the web-based management interface of Cisco Firepower Management Center (FMC) Software could allow an authenticated, remote attacker to conduct SQL injection attacks on an affected system. This vulnerability exists because the web-based management interface does not adequately validate user input. An attacker could exploit this vulnerability by authenticating to the application and sending crafted SQL queries to an affected system. A successful exploit could allow the attacker to obtain any data from the database, execute arbitrary commands on the underlying operating system, and elevate privileges to root. To exploit this vulnerability, an attacker would need at least Read Only user credentials.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2024-05-22
Published