cbcvebase.

Cisco Firepower Management Center vulnerabilities

128 known vulnerabilities affecting cisco/cisco_firepower_management_center.

Total CVEs
128
CISA KEV
0
Public exploits
2
Exploited in wild
0
Severity breakdown
CRITICAL5HIGH31MEDIUM92

Vulnerabilities

Page 3 of 7
CVE-2025-20301P3MEDIUMCVSS 6.5v6.2.3.12v6.2.3.1+91 more2025-08-14
CVE-2025-20301 [MEDIUM] CWE-862 CVE-2025-20301: A vulnerability in the web-based management interface of Cisco Secure FMC Software could allow an au A vulnerability in the web-based management interface of Cisco Secure FMC Software could allow an authenticated, low-privileged, remote attacker to access troubleshoot files for a different domain. This vulnerability is due to missing authorization checks. An attacker could exploit this vulnerability by directly accessing a troubleshoot file for a
nvd
CVE-2024-20471P3MEDIUMCVSS 6.5v6.2.3v6.2.3.1+89 more2024-10-23
CVE-2024-20471 [MEDIUM] CWE-89 CVE-2024-20471: A vulnerability in the web-based management interface of Cisco Secure Firewall Management Center (FM A vulnerability in the web-based management interface of Cisco Secure Firewall Management Center (FMC) Software could allow an authenticated, remote attacker to conduct SQL injection attacks on an affected system. This vulnerability exists because the web-based management interface does not validate user input adequately. An attacker could exploit th
nvd
CVE-2024-20473P3MEDIUMCVSS 6.5v7.3.0v7.3.1+5 more2024-10-23
CVE-2024-20473 [MEDIUM] CWE-89 CVE-2024-20473: A vulnerability in the web-based management interface of Cisco Secure Firewall Management Center (FM A vulnerability in the web-based management interface of Cisco Secure Firewall Management Center (FMC) Software could allow an authenticated, remote attacker to conduct SQL injection attacks on an affected system. This vulnerability exists because the web-based management interface does not validate user input adequately. An attacker could exploit t
nvd
CVE-2024-20472P3MEDIUMCVSS 6.5v7.3.0v7.3.1+5 more2024-10-23
CVE-2024-20472 [MEDIUM] CWE-89 CVE-2024-20472: A vulnerability in the web-based management interface of Cisco Secure Firewall Management Center (FM A vulnerability in the web-based management interface of Cisco Secure Firewall Management Center (FMC) Software could allow an authenticated, remote attacker to conduct SQL injection attacks on an affected system. This vulnerability exists because the web-based management interface does not validate user input adequately. An attacker could exploit t
nvd
CVE-2022-20744P3MEDIUMCVSS 6.5vn/a2022-05-03
CVE-2022-20744 [MEDIUM] CWE-807 CVE-2022-20744: A vulnerability in the input protection mechanisms of Cisco Firepower Management Center (FMC) Softwa A vulnerability in the input protection mechanisms of Cisco Firepower Management Center (FMC) Software could allow an authenticated, remote attacker to view data without proper authorization. This vulnerability exists because of a protection mechanism that relies on the existence or values of a specific input. An attacker could exploit this vulnerab
nvd
CVE-2024-20275P3MEDIUMCVSS 6.1v7.1.0v7.1.0.1+20 more2024-10-23
CVE-2024-20275 [MEDIUM] CWE-78 CVE-2024-20275: A vulnerability in the cluster backup feature of Cisco Secure Firewall Management Center (FMC) Softw A vulnerability in the cluster backup feature of Cisco Secure Firewall Management Center (FMC) Software, formerly Firepower Management Center Software, could allow an authenticated, remote attacker to execute arbitrary commands on the underlying operating system. This vulnerability is due to insufficient validation of user data that is supplied thro
nvd
CVE-2023-20155P3MEDIUMCVSS 6.5v6.2.3v6.2.3.1+70 more2023-11-01
CVE-2023-20155 [MEDIUM] CWE-770 CVE-2023-20155: A vulnerability in a logging API in Cisco Firepower Management Center (FMC) Software could allow an A vulnerability in a logging API in Cisco Firepower Management Center (FMC) Software could allow an unauthenticated, remote attacker to cause the device to become unresponsive or trigger an unexpected reload. This vulnerability could also allow an attacker with valid user credentials, but not Administrator privileges, to view a system log file that t
nvd
CVE-2025-20220P3MEDIUMCVSS 6.0v7.2.6v7.2.7+8 more2025-08-14
CVE-2025-20220 [MEDIUM] CWE-78 CVE-2025-20220: A vulnerability in the CLI of Cisco Secure Firewall Management Center (FMC) Software and Cisco Secur A vulnerability in the CLI of Cisco Secure Firewall Management Center (FMC) Software and Cisco Secure Firewall Threat Defense (FTD) Software could allow an authenticated, local attacker to execute arbitrary commands on the underlying operating system as root. This vulnerability is due to improper input validation for specific CLI commands. An attacke
nvd
CVE-2019-12700P3MEDIUMCVSS 6.5≥ unspecified, < n/a2019-10-02
CVE-2019-12700 [MEDIUM] CWE-400 CVE-2019-12700: A vulnerability in the configuration of the Pluggable Authentication Module (PAM) used in Cisco Fire A vulnerability in the configuration of the Pluggable Authentication Module (PAM) used in Cisco Firepower Threat Defense (FTD) Software, Cisco Firepower Management Center (FMC) Software, and Cisco FXOS Software could allow an authenticated, remote attacker to cause a denial of service (DoS) condition. The vulnerability is due to improper resource ma
nvd
CVE-2019-12701P3MEDIUMCVSS 5.8≥ unspecified, < n/a2019-10-02
CVE-2019-12701 [MEDIUM] CWE-20 CVE-2019-12701: A vulnerability in the file and malware inspection feature of Cisco Firepower Management Center (FMC A vulnerability in the file and malware inspection feature of Cisco Firepower Management Center (FMC) Software could allow an unauthenticated, remote attacker to bypass the file and malware inspection policies on an affected system. The vulnerability exists because the affected software insufficiently validates incoming traffic. An attacker could exp
nvd
CVE-2024-20361P4MEDIUMCVSS 5.8v7.1.0v7.1.0.1+10 more2024-05-22
CVE-2024-20361 [MEDIUM] CWE-264 CVE-2024-20361: A vulnerability in the Object Groups for Access Control Lists (ACLs) feature of Cisco Firepower Mana A vulnerability in the Object Groups for Access Control Lists (ACLs) feature of Cisco Firepower Management Center (FMC) Software could allow an unauthenticated, remote attacker to bypass configured access controls on managed devices that are running Cisco Firepower Threat Defense (FTD) Software. This vulnerability is due to the incorrect deployment
nvd
CVE-2024-20388P4MEDIUMCVSS 5.3v6.2.3v6.2.3.1+89 more2024-10-23
CVE-2024-20388 [MEDIUM] CWE-202 CVE-2024-20388: A vulnerability in the password change feature of Cisco Firepower Management Center (FMC) software c A vulnerability in the password change feature of Cisco Firepower Management Center (FMC) software could allow an unauthenticated, remote attacker to determine valid user names on an affected device. This vulnerability is due to improper authentication of password update responses. An attacker could exploit this vulnerability by forcing a password r
nvd
CVE-2019-12691P4MEDIUMCVSS 4.9≥ unspecified, < n/a2019-10-02
CVE-2019-12691 [MEDIUM] CWE-22 CVE-2019-12691: A vulnerability in the web-based management interface of Cisco Firepower Management Center (FMC) Sof A vulnerability in the web-based management interface of Cisco Firepower Management Center (FMC) Software could allow an authenticated, remote attacker to perform a directory traversal attack on an affected device. The vulnerability is due to insufficient input validation by the web-based management interface. An attacker could exploit this vulnerabi
nvd
CVE-2025-20306P4MEDIUMCVSS 4.9v6.2.3.12v6.2.3.1+93 more2025-08-14
CVE-2025-20306 [MEDIUM] CWE-77 CVE-2025-20306: A vulnerability in the web-based management interface of Cisco Secure Firewall Management Center (FM A vulnerability in the web-based management interface of Cisco Secure Firewall Management Center (FMC) Software could allow an authenticated, remote attacker with Administrator-level privileges to execute arbitrary commands on the underlying operating system. This vulnerability is due to insufficient input validation of certain HTTP request paramete
nvd
CVE-2019-1982P4MEDIUMCVSS 5.3≥ unspecified, < n/a2019-11-05
CVE-2019-1982 [MEDIUM] CWE-264 CVE-2019-1982: A vulnerability in the HTTP traffic filtering component of Cisco Firepower Threat Defense Software, A vulnerability in the HTTP traffic filtering component of Cisco Firepower Threat Defense Software, Cisco FirePOWER Services Software for ASA, and Cisco Firepower Management Center Software could allow an unauthenticated, remote attacker to bypass filtering protections. The vulnerability is due to improper handling of HTTP requests, including those com
nvd
CVE-2020-3307P4MEDIUMCVSS 5.3vn/a2020-05-06
CVE-2020-3307 [MEDIUM] CWE-20 CVE-2020-3307: A vulnerability in the web UI of Cisco Firepower Management Center (FMC) Software could allow an una A vulnerability in the web UI of Cisco Firepower Management Center (FMC) Software could allow an unauthenticated, remote attacker to write arbitrary entries to the log file on an affected device. The vulnerability is due to insufficient input validation. An attacker could exploit this vulnerability by sending a crafted HTTP request to an affected devic
nvd
CVE-2024-20274P4MEDIUMCVSS 5.5v6.2.3.12v6.2.3.1+84 more2024-10-23
CVE-2024-20274 [MEDIUM] CWE-20 CVE-2024-20274: A vulnerability in the web-based management interface of Cisco Secure Firewall Management Center (FM A vulnerability in the web-based management interface of Cisco Secure Firewall Management Center (FMC) Software, formerly Firepower Management Center Software, could allow an authenticated, remote attacker to inject arbitrary HTML content into a device-generated document. This vulnerability is due to improper validation of user-supplied data. An att
nvd
CVE-2022-20941P4MEDIUMCVSS 5.3v6.2.3v6.2.3.1+60 more2022-11-15
CVE-2022-20941 [MEDIUM] CWE-334 CVE-2022-20941: A vulnerability in the web-based management interface of Cisco Firepower Management Center (FMC) Sof A vulnerability in the web-based management interface of Cisco Firepower Management Center (FMC) Software could allow an unauthenticated, remote attacker to access sensitive information. This vulnerability is due to missing authorization for certain resources in the web-based management interface together with insufficient entropy in these resource
nvd
CVE-2020-3311P4MEDIUMCVSS 6.1vn/a2020-05-06
CVE-2020-3311 [MEDIUM] CWE-601 CVE-2020-3311: A vulnerability in the web interface of Cisco Firepower Management Center (FMC) Software could allow A vulnerability in the web interface of Cisco Firepower Management Center (FMC) Software could allow an unauthenticated, remote attacker to redirect a user to a malicious web page. The vulnerability is due to improper input validation of HTTP request parameters. An attacker could exploit this vulnerability by intercepting and modifying an HTTP request
nvd
CVE-2020-3558P4MEDIUMCVSS 6.1vn/a2020-10-21
CVE-2020-3558 [MEDIUM] CWE-601 CVE-2020-3558: A vulnerability in the web-based management interface of Cisco Firepower Management Center (FMC) Sof A vulnerability in the web-based management interface of Cisco Firepower Management Center (FMC) Software could allow an unauthenticated, remote attacker to redirect a user to a malicious web page. The vulnerability is due to improper input validation of the parameters of an HTTP request. An attacker could exploit this vulnerability by intercepting an
nvd