Cisco Firepower Management Center vulnerabilities
128 known vulnerabilities affecting cisco/cisco_firepower_management_center.
Total CVEs
128
CISA KEV
0
Public exploits
2
Exploited in wild
0
Severity breakdown
CRITICAL5HIGH31MEDIUM92
Vulnerabilities
Page 2 of 7
CVE-2022-20926P2HIGHCVSS 8.8v7.0.0v7.0.0.1+9 more2022-11-15
CVE-2022-20926 [HIGH] CWE-77 CVE-2022-20926: A vulnerability in the web management interface of the Cisco Firepower Management Center (FMC) Softw
A vulnerability in the web management interface of the Cisco Firepower Management Center (FMC) Software could allow an authenticated, remote attacker to execute arbitrary commands on the underlying operating system.
The vulnerability is due to insufficient validation of user-supplied parameters for certain API endpoints. An attacker could exploit this
nvd
CVE-2025-20148P2HIGHCVSS 8.5v7.2.4v7.0.6+17 more2025-08-14
CVE-2025-20148 [HIGH] CWE-20 CVE-2025-20148: A vulnerability in the web-based management interface of Cisco Secure Firewall Management Center (FM
A vulnerability in the web-based management interface of Cisco Secure Firewall Management Center (FMC) Software could allow an authenticated, remote attacker to inject arbitrary HTML content into a device-generated document.
This vulnerability is due to improper validation of user-supplied data. An attacker could exploit this vulnerability by submitti
nvd
CVE-2021-34762P3HIGHCVSS 8.1vn/a2021-10-27
CVE-2021-34762 [HIGH] CWE-26 CVE-2021-34762: A vulnerability in the web-based management interface of Cisco Firepower Management Center (FMC) Sof
A vulnerability in the web-based management interface of Cisco Firepower Management Center (FMC) Software could allow an authenticated, remote attacker to perform a directory traversal attack on an affected device. The attacker would require valid device credentials. The vulnerability is due to insufficient input validation of the HTTPS URL by the web-
nvd
CVE-2020-3550P3HIGHCVSS 8.1vn/a2020-10-21
CVE-2020-3550 [HIGH] CWE-22 CVE-2020-3550: A vulnerability in the sfmgr daemon of Cisco Firepower Management Center (FMC) Software and Cisco Fi
A vulnerability in the sfmgr daemon of Cisco Firepower Management Center (FMC) Software and Cisco Firepower Threat Defense (FTD) Software could allow an authenticated, remote attacker to perform directory traversal and access directories outside the restricted path. The vulnerability is due to insufficient input validation. An attacker could exploit this
nvd
CVE-2020-3318P3CRITICALCVSS 9.8vn/a2020-05-06
CVE-2020-3318 [CRITICAL] CWE-798 CVE-2020-3318: Multiple vulnerabilities in Cisco Firepower Management Center (FMC) Software and Cisco Firepower Use
Multiple vulnerabilities in Cisco Firepower Management Center (FMC) Software and Cisco Firepower User Agent Software could allow an attacker to access a sensitive part of an affected system with a high-privileged account. For more information about these vulnerabilities, see the Details section of this advisory.
nvd
CVE-2020-3302P3HIGHCVSS 8.1vn/a2020-05-06
CVE-2020-3302 [HIGH] CWE-20 CVE-2020-3302: A vulnerability in the web UI of Cisco Firepower Management Center (FMC) Software could allow an aut
A vulnerability in the web UI of Cisco Firepower Management Center (FMC) Software could allow an authenticated, remote attacker to overwrite files on the file system of an affected device. The vulnerability is due to insufficient input validation. An attacker could exploit this vulnerability by uploading a crafted file to the web UI on an affected device
nvd
CVE-2020-3410P3HIGHCVSS 8.1vn/a2020-10-21
CVE-2020-3410 [HIGH] CWE-287 CVE-2020-3410: A vulnerability in the Common Access Card (CAC) authentication feature of Cisco Firepower Management
A vulnerability in the Common Access Card (CAC) authentication feature of Cisco Firepower Management Center (FMC) Software could allow an unauthenticated, remote attacker to bypass authentication and access the FMC system. The attacker must have a valid CAC to initiate the access attempt. The vulnerability is due to incorrect session invalidation during
nvd
CVE-2024-20374P3HIGHCVSS 7.2v6.7.0v6.7.0.1+40 more2024-10-23
CVE-2024-20374 [HIGH] CWE-269 CVE-2024-20374: A vulnerability in the web-based management interface of Cisco Secure Firewall Management Center (FM
A vulnerability in the web-based management interface of Cisco Secure Firewall Management Center (FMC) Software, formerly Firepower Management Center Software, could allow an authenticated, remote attacker with Administrator-level privileges to execute arbitrary commands on the underlying operating system.
This vulnerability is due to insufficient inp
nvd
CVE-2019-12690P3HIGHCVSS 7.2≥ unspecified, < n/a2019-10-02
CVE-2019-12690 [HIGH] CWE-78 CVE-2019-12690: A vulnerability in the web UI of the Cisco Firepower Management Center (FMC) could allow an authenti
A vulnerability in the web UI of the Cisco Firepower Management Center (FMC) could allow an authenticated, remote attacker to inject arbitrary commands that are executed with the privileges of the root user of the underlying operating system. The vulnerability is due to insufficient validation of user-supplied input to the web UI. An attacker could exp
nvd
CVE-2020-3499P3HIGHCVSS 8.6vn/a2020-10-21
CVE-2020-3499 [HIGH] CWE-399 CVE-2020-3499: A vulnerability in the licensing service of Cisco Firepower Management Center (FMC) Software could a
A vulnerability in the licensing service of Cisco Firepower Management Center (FMC) Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition.The vulnerability is due to improper handling of system resource values by the affected system. An attacker could exploit this vulnerability by sending malicious request
nvd
CVE-2018-15443P3HIGHCVSS 7.5vn/a2018-11-08
CVE-2018-15443 [HIGH] CWE-400 CVE-2018-15443: A vulnerability in the detection engine of Cisco Firepower System Software could allow an unauthenti
A vulnerability in the detection engine of Cisco Firepower System Software could allow an unauthenticated, remote attacker to bypass a configured Intrusion Prevention System (IPS) rule that inspects certain types of TCP traffic. The vulnerability is due to incorrect TCP retransmission handling. An attacker could exploit this vulnerability by sending a
nvd
CVE-2020-3549P3HIGHCVSS 8.1vn/a2020-10-21
CVE-2020-3549 [HIGH] CWE-326 CVE-2020-3549: A vulnerability in the sftunnel functionality of Cisco Firepower Management Center (FMC) Software an
A vulnerability in the sftunnel functionality of Cisco Firepower Management Center (FMC) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to obtain the device registration hash. The vulnerability is due to insufficient sftunnel negotiation protection during initial device registration. An attacke
nvd
CVE-2022-20918P3HIGHCVSS 7.5v7.0.0v7.0.0.1+6 more2022-11-15
CVE-2022-20918 [HIGH] CWE-284 CVE-2022-20918: A vulnerability in the Simple Network Management Protocol (SNMP) access controls for Cisco FirePOWER
A vulnerability in the Simple Network Management Protocol (SNMP) access controls for Cisco FirePOWER Software for Adaptive Security Appliance (ASA) FirePOWER module, Cisco Firepower Management Center (FMC) Software, and Cisco Next-Generation Intrusion Prevention System (NGIPS) Software could allow an unauthenticated, remote attacker to perform an SNMP
nvd
CVE-2022-20925P3HIGHCVSS 7.2v6.7.0v6.7.0.1+13 more2022-11-15
CVE-2022-20925 [HIGH] CWE-77 CVE-2022-20925: A vulnerability in the web management interface of the Cisco Firepower Management Center (FMC) Softw
A vulnerability in the web management interface of the Cisco Firepower Management Center (FMC) Software could allow an authenticated, remote attacker to execute arbitrary commands on the underlying operating system.
The vulnerability is due to insufficient validation of user-supplied parameters for certain API endpoints. An attacker could exploit this
nvd
CVE-2023-20063P3HIGHCVSS 8.2v6.2.3.12v6.2.3.1+89 more2023-11-01
CVE-2023-20063 [HIGH] CWE-94 CVE-2023-20063: A vulnerability in the inter-device communication mechanisms between devices that are running Cisco
A vulnerability in the inter-device communication mechanisms between devices that are running Cisco Firepower Threat Defense (FTD) Software and devices that are running Cisco Firepower Management (FMC) Software could allow an authenticated, local attacker to execute arbitrary commands with root permissions on the underlying operating system of an affect
nvd
CVE-2024-20379P3MEDIUMCVSS 6.5v7.3.0v7.3.1+5 more2024-10-23
CVE-2024-20379 [MEDIUM] CWE-36 CVE-2024-20379: A vulnerability in the web-based management interface of Cisco Secure Firewall Management Center (FM
A vulnerability in the web-based management interface of Cisco Secure Firewall Management Center (FMC) Software, formerly Firepower Management Center Software, could allow an authenticated, remote attacker to read arbitrary files from the underlying operating system.
This vulnerability exists because the web-based management interface does not proper
nvd
CVE-2018-15458P3HIGHCVSS 7.5vn/a2019-01-10
CVE-2018-15458 [HIGH] CWE-399 CVE-2018-15458: A vulnerability in the Shell Access Filter feature of Cisco Firepower Management Center (FMC), when
A vulnerability in the Shell Access Filter feature of Cisco Firepower Management Center (FMC), when used in conjunction with remote authentication, could allow an unauthenticated, remote attacker to cause high disk utilization, resulting in a denial of service (DoS) condition. The vulnerability occurs because the configuration of the Shell Access Filte
nvd
CVE-2023-20114P3MEDIUMCVSS 6.5v6.7.0v6.7.0.1+24 more2023-11-01
CVE-2023-20114 [MEDIUM] CWE-73 CVE-2023-20114: A vulnerability in the file download feature of Cisco Firepower Management Center (FMC) Software cou
A vulnerability in the file download feature of Cisco Firepower Management Center (FMC) Software could allow an authenticated, remote attacker to download arbitrary files from an affected system. This vulnerability is due to a lack of input sanitation. An attacker could exploit this vulnerability by sending a crafted HTTPS request. A successful explo
nvd
CVE-2022-20854P3HIGHCVSS 7.5vN/A2022-11-15
CVE-2022-20854 [HIGH] CWE-400 CVE-2022-20854: A vulnerability in the processing of SSH connections of Cisco Firepower Management Center (FMC) and
A vulnerability in the processing of SSH connections of Cisco Firepower Management Center (FMC) and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device.
This vulnerability is due to improper error handling when an SSH session fails to be establi
nvd
CVE-2024-20482P3MEDIUMCVSS 6.5v7.2.0v7.2.1+17 more2024-10-23
CVE-2024-20482 [MEDIUM] CWE-863 CVE-2024-20482: A vulnerability in the web-based management interface of Cisco Secure Firewall Management Center (FM
A vulnerability in the web-based management interface of Cisco Secure Firewall Management Center (FMC) Software, formerly Firepower Management Center Software, could allow an authenticated, remote attacker to elevate privileges on an affected device. To exploit this vulnerability, an attacker must have a valid account on the device that is configure
nvd