cbcvebase.

Cisco Firepower Management Center vulnerabilities

128 known vulnerabilities affecting cisco/cisco_firepower_management_center.

Total CVEs
128
CISA KEV
0
Public exploits
2
Exploited in wild
0
Severity breakdown
CRITICAL5HIGH31MEDIUM92

Vulnerabilities

Page 1 of 7
CVE-2023-20048P2CRITICALCVSS 9.9PoCv6.2.3v6.2.3.1+70 more2023-11-01
CVE-2023-20048 [CRITICAL] CWE-269 CVE-2023-20048: A vulnerability in the web services interface of Cisco Firepower Management Center (FMC) Software co A vulnerability in the web services interface of Cisco Firepower Management Center (FMC) Software could allow an authenticated, remote attacker to execute certain unauthorized configuration commands on a Firepower Threat Defense (FTD) device that is managed by the FMC Software. This vulnerability is due to insufficient authorization of configurati
nvd
CVE-2025-20265P1CRITICALCVSS 10.0v7.0.7v7.7.02025-08-14
CVE-2025-20265 [CRITICAL] CWE-74 CVE-2025-20265: A vulnerability in the RADIUS subsystem implementation of Cisco Secure Firewall Management Center (F A vulnerability in the RADIUS subsystem implementation of Cisco Secure Firewall Management Center (FMC) Software could allow an unauthenticated, remote attacker to inject arbitrary shell commands that are executed by the device. This vulnerability is due to a lack of proper handling of user input during the authentication phase. An attacker could
nvd
CVE-2024-20424P2CRITICALCVSS 9.9v6.2.3v6.2.3.1+90 more2024-10-23
CVE-2024-20424 [CRITICAL] CWE-78 CVE-2024-20424: A vulnerability in the web-based management interface of Cisco Secure Firewall Management Center (FM A vulnerability in the web-based management interface of Cisco Secure Firewall Management Center (FMC) Software, formerly Firepower Management Center Software, could allow an authenticated, remote attacker to execute arbitrary commands on the underlying operating system as root. This vulnerability is due to insufficient input validation of certain
nvd
CVE-2019-16028P2CRITICALCVSS 9.8vn/a2020-09-23
CVE-2019-16028 [CRITICAL] CWE-287 CVE-2019-16028: A vulnerability in the web-based management interface of Cisco Firepower Management Center (FMC) cou A vulnerability in the web-based management interface of Cisco Firepower Management Center (FMC) could allow an unauthenticated, remote attacker to bypass authentication and execute arbitrary actions with administrative privileges on an affected device. The vulnerability is due to improper handling of Lightweight Directory Access Protocol (LDAP) a
nvd
CVE-2022-20743P2HIGHCVSS 8.8vn/a2022-05-03
CVE-2022-20743 [HIGH] CWE-434 CVE-2022-20743: A vulnerability in the web management interface of Cisco Firepower Management Center (FMC) Software A vulnerability in the web management interface of Cisco Firepower Management Center (FMC) Software could allow an authenticated, remote attacker to bypass security protections and upload malicious files to the affected system. This vulnerability is due to improper validation of files uploaded to the web management interface of Cisco FMC Software. An a
nvd
CVE-2019-1642P3MEDIUMCVSS 6.1PoCvn/a2019-01-23
CVE-2019-1642 [MEDIUM] CWE-79 CVE-2019-1642: A vulnerability in the web-based management interface of Cisco Firepower Management Center (FMC) sof A vulnerability in the web-based management interface of Cisco Firepower Management Center (FMC) software could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web-based management interface of the affected software. The vulnerability is due to insufficient validation of user-supplied input
nvd
CVE-2023-20220P2HIGHCVSS 8.8v6.2.3v6.2.3.1+71 more2023-11-01
CVE-2023-20220 [HIGH] CWE-22 CVE-2023-20220: Multiple vulnerabilities in the web-based management interface of Cisco Firepower Management Center Multiple vulnerabilities in the web-based management interface of Cisco Firepower Management Center (FMC) Software could allow an authenticated, remote attacker to execute arbitrary commands on the underlying operating system. To exploit these vulnerabilities, the attacker must have valid device credentials, but does not need Administrator privileges. T
nvd
CVE-2023-20219P2HIGHCVSS 8.8v6.7.0v6.7.0.1+25 more2023-11-01
CVE-2023-20219 [HIGH] CWE-78 CVE-2023-20219: Multiple vulnerabilities in the web management interface of Cisco Firepower Management Center (FMC) Multiple vulnerabilities in the web management interface of Cisco Firepower Management Center (FMC) Software could allow an authenticated, remote attacker to execute arbitrary commands on the underlying operating system. The attacker would need valid device credentials but does not require administrator privileges to exploit this vulnerability. These vu
nvd
CVE-2024-20360P2HIGHCVSS 8.8v7.0.0v7.0.0.1+25 more2024-05-22
CVE-2024-20360 [HIGH] CWE-89 CVE-2024-20360: A vulnerability in the web-based management interface of Cisco Firepower Management Center (FMC) Sof A vulnerability in the web-based management interface of Cisco Firepower Management Center (FMC) Software could allow an authenticated, remote attacker to conduct SQL injection attacks on an affected system. This vulnerability exists because the web-based management interface does not adequately validate user input. An attacker could exploit this vulne
nvd
CVE-2019-12689P2HIGHCVSS 8.8≥ unspecified, < n/a2019-10-02
CVE-2019-12689 [HIGH] CWE-20 CVE-2019-12689: A vulnerability in the web-based management interface of Cisco Firepower Management Center (FMC) Sof A vulnerability in the web-based management interface of Cisco Firepower Management Center (FMC) Software could allow an authenticated, remote attacker to execute arbitrary code on the underlying operating system of an affected device. The vulnerability is due to insufficient input validation. An attacker could exploit this vulnerability by sending mal
nvd
CVE-2019-12679P2HIGHCVSS 8.8≥ unspecified, < n/a2019-10-02
CVE-2019-12679 [HIGH] CWE-89 CVE-2019-12679: Multiple vulnerabilities in the web-based management interface of Cisco Firepower Management Center Multiple vulnerabilities in the web-based management interface of Cisco Firepower Management Center (FMC) Software could allow an authenticated, remote attacker to execute arbitrary SQL injections on an affected device. These vulnerabilities exist due to improper input validation. An attacker could exploit these vulnerabilities by sending crafted SQL qu
nvd
CVE-2019-12681P2HIGHCVSS 8.8≥ unspecified, < n/a2019-10-02
CVE-2019-12681 [HIGH] CWE-89 CVE-2019-12681: Multiple vulnerabilities in the web-based management interface of Cisco Firepower Management Center Multiple vulnerabilities in the web-based management interface of Cisco Firepower Management Center (FMC) Software could allow an authenticated, remote attacker to execute arbitrary SQL injections on an affected device. These vulnerabilities exist due to improper input validation. An attacker could exploit these vulnerabilities by sending crafted SQL qu
nvd
CVE-2019-12685P2HIGHCVSS 8.8≥ unspecified, < n/a2019-10-02
CVE-2019-12685 [HIGH] CWE-89 CVE-2019-12685: Multiple vulnerabilities in the web-based management interface of Cisco Firepower Management Center Multiple vulnerabilities in the web-based management interface of Cisco Firepower Management Center (FMC) Software could allow an authenticated, remote attacker to execute arbitrary SQL injections on an affected device. These vulnerabilities exist due to improper input validation. An attacker could exploit these vulnerabilities by sending crafted SQL qu
nvd
CVE-2019-12682P2HIGHCVSS 8.8≥ unspecified, < n/a2019-10-02
CVE-2019-12682 [HIGH] CWE-89 CVE-2019-12682: Multiple vulnerabilities in the web-based management interface of Cisco Firepower Management Center Multiple vulnerabilities in the web-based management interface of Cisco Firepower Management Center (FMC) Software could allow an authenticated, remote attacker to execute arbitrary SQL injections on an affected device. These vulnerabilities exist due to improper input validation. An attacker could exploit these vulnerabilities by sending crafted SQL qu
nvd
CVE-2019-12683P2HIGHCVSS 8.8≥ unspecified, < n/a2019-10-02
CVE-2019-12683 [HIGH] CWE-89 CVE-2019-12683: Multiple vulnerabilities in the web-based management interface of Cisco Firepower Management Center Multiple vulnerabilities in the web-based management interface of Cisco Firepower Management Center (FMC) Software could allow an authenticated, remote attacker to execute arbitrary SQL injections on an affected device. These vulnerabilities exist due to improper input validation. An attacker could exploit these vulnerabilities by sending crafted SQL qu
nvd
CVE-2019-12684P2HIGHCVSS 8.8≥ unspecified, < n/a2019-10-02
CVE-2019-12684 [HIGH] CWE-89 CVE-2019-12684: Multiple vulnerabilities in the web-based management interface of Cisco Firepower Management Center Multiple vulnerabilities in the web-based management interface of Cisco Firepower Management Center (FMC) Software could allow an authenticated, remote attacker to execute arbitrary SQL injections on an affected device. These vulnerabilities exist due to improper input validation. An attacker could exploit these vulnerabilities by sending crafted SQL qu
nvd
CVE-2019-12686P2HIGHCVSS 8.8≥ unspecified, < n/a2019-10-02
CVE-2019-12686 [HIGH] CWE-89 CVE-2019-12686: Multiple vulnerabilities in the web-based management interface of Cisco Firepower Management Center Multiple vulnerabilities in the web-based management interface of Cisco Firepower Management Center (FMC) Software could allow an authenticated, remote attacker to execute arbitrary SQL injections on an affected device. These vulnerabilities exist due to improper input validation. An attacker could exploit these vulnerabilities by sending crafted SQL qu
nvd
CVE-2019-12680P2HIGHCVSS 8.8≥ unspecified, < n/a2019-10-02
CVE-2019-12680 [HIGH] CWE-89 CVE-2019-12680: Multiple vulnerabilities in the web-based management interface of Cisco Firepower Management Center Multiple vulnerabilities in the web-based management interface of Cisco Firepower Management Center (FMC) Software could allow an authenticated, remote attacker to execute arbitrary SQL injections on an affected device. These vulnerabilities exist due to improper input validation. An attacker could exploit these vulnerabilities by sending crafted SQL qu
nvd
CVE-2019-12687P2HIGHCVSS 8.8≥ unspecified, < n/a2019-10-02
CVE-2019-12687 [HIGH] CWE-119 CVE-2019-12687: A vulnerability in the web UI of the Cisco Firepower Management Center (FMC) could allow an authenti A vulnerability in the web UI of the Cisco Firepower Management Center (FMC) could allow an authenticated, remote attacker to execute arbitrary commands on an affected device. The vulnerability is due to insufficient input validation. An attacker could exploit this vulnerability by sending crafted input to the web UI. A successful exploit could allow
nvd
CVE-2019-12688P2HIGHCVSS 8.8≥ unspecified, < n/a2019-10-02
CVE-2019-12688 [HIGH] CWE-119 CVE-2019-12688: A vulnerability in the web UI of the Cisco Firepower Management Center (FMC) could allow an authenti A vulnerability in the web UI of the Cisco Firepower Management Center (FMC) could allow an authenticated, remote attacker to execute arbitrary commands on an affected device. The vulnerability is due to insufficient input validation. An attacker could exploit this vulnerability by sending crafted input to the web UI. A successful exploit could allow
nvd
Cisco Firepower Management Center vulnerabilities | cvebase