cbcvebase.
CVE-2024-20360
published 2024-05-22

CVE-2024-20360: A vulnerability in the web-based management interface of Cisco Firepower Management Center (FMC) Software could allow an authenticated, remote attacker to…

PriorityP262high8.8CVSS 3.1
AVNACLPRLUINSUCHIHAH
EPSS
0.84%
53.7th percentile
A vulnerability in the web-based management interface of Cisco Firepower Management Center (FMC) Software could allow an authenticated, remote attacker to conduct SQL injection attacks on an affected system. This vulnerability exists because the web-based management interface does not adequately validate user input. An attacker could exploit this vulnerability by authenticating to the application and sending crafted SQL queries to an affected system. A successful exploit could allow the attacker to obtain any data from the database, execute arbitrary commands on the underlying operating system, and elevate privileges to root. To exploit this vulnerability, an attacker would need at least Read Only user credentials.

Affected

55 ranges· showing 25
VendorProductVersion rangeFixed in
ciscocisco_firepower_management_center
ciscocisco_firepower_management_center
ciscocisco_firepower_management_center
ciscocisco_firepower_management_center
ciscocisco_firepower_management_center
ciscocisco_firepower_management_center
ciscocisco_firepower_management_center
ciscocisco_firepower_management_center
ciscocisco_firepower_management_center
ciscocisco_firepower_management_center
ciscocisco_firepower_management_center
ciscocisco_firepower_management_center
ciscocisco_firepower_management_center
ciscocisco_firepower_management_center
ciscocisco_firepower_management_center
ciscocisco_firepower_management_center
ciscocisco_firepower_management_center
ciscocisco_firepower_management_center
ciscocisco_firepower_management_center
ciscocisco_firepower_management_center
ciscocisco_firepower_management_center
ciscocisco_firepower_management_center
ciscocisco_firepower_management_center
ciscocisco_firepower_management_center
ciscocisco_firepower_management_center

Detection & IOCsextracted from sources · hover to see the quote

  • Exploit requires at least Read Only user credentials authenticating to the Cisco FMC web-based management interface and sending crafted SQL queries
  • Successful exploitation can result in OS command execution and privilege escalation to root — monitor FMC for unexpected OS-level process spawning from web service accounts
  • Track Cisco internal Bug ID CSCwf92182 for patch and indicator updates related to this vulnerability
  • ·No workarounds are available; the only remediation is applying Cisco-released software updates
  • ·Exploitation requires authentication — at minimum Read Only credentials — meaning unauthenticated access alone is insufficient to trigger the vulnerability

CVSS provenance

nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
vendor_cisco8.8HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.