Cisco Firepower Management Center vulnerabilities
128 known vulnerabilities affecting cisco/cisco_firepower_management_center.
Total CVEs
128
CISA KEV
0
Public exploits
2
Exploited in wild
0
Severity breakdown
CRITICAL5HIGH31MEDIUM92
Vulnerabilities
Page 4 of 7
CVE-2024-20273P4MEDIUMCVSS 6.1v6.2.3.12v6.2.3.1+81 more2024-10-23
CVE-2024-20273 [MEDIUM] CWE-79 CVE-2024-20273: A vulnerability in the web-based management interface of Cisco Firepower Management Center (FMC) Sof
A vulnerability in the web-based management interface of Cisco Firepower Management Center (FMC) Software could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface of an affected device. This vulnerability is due to insufficient validation of user-supplied input by the web-based man
nvd
CVE-2023-20206P4MEDIUMCVSS 6.1v6.6.0v6.6.0.1+35 more2023-11-01
CVE-2023-20206 [MEDIUM] CWE-79 CVE-2023-20206: Multiple vulnerabilities in the web-based management interface of Cisco Firepower Management Center
Multiple vulnerabilities in the web-based management interface of Cisco Firepower Management Center (FMC) Software could allow an unauthenticated, remote attacker to conduct a stored cross-site scripting (XSS) attack against a user of the interface of an affected device. These vulnerabilities are due to insufficient validation of user-supplied input b
nvd
CVE-2023-20005P4MEDIUMCVSS 6.1v6.2.3v6.2.3.1+68 more2023-11-01
CVE-2023-20005 [MEDIUM] CWE-79 CVE-2023-20005: Multiple vulnerabilities in the web-based management interface of Cisco Firepower Management Center
Multiple vulnerabilities in the web-based management interface of Cisco Firepower Management Center (FMC) Software could allow an unauthenticated, remote attacker to conduct a stored cross-site scripting (XSS) attack against a user of the interface of an affected device. These vulnerabilities are due to insufficient validation of user-supplied input b
nvd
CVE-2023-20074P4MEDIUMCVSS 6.1v6.2.3v6.2.3.1+71 more2023-11-01
CVE-2023-20074 [MEDIUM] CWE-79 CVE-2023-20074: Multiple vulnerabilities in the web-based management interface of Cisco Firepower Management Center
Multiple vulnerabilities in the web-based management interface of Cisco Firepower Management Center (FMC) Software could allow an unauthenticated, remote attacker to conduct a stored cross-site scripting (XSS) attack against a user of the interface of an affected device. These vulnerabilities are due to insufficient validation of user-supplied input b
nvd
CVE-2023-20041P4MEDIUMCVSS 6.1v6.4.0.16v6.6.7.1+8 more2023-11-01
CVE-2023-20041 [MEDIUM] CWE-79 CVE-2023-20041: Multiple vulnerabilities in the web-based management interface of Cisco Firepower Management Center
Multiple vulnerabilities in the web-based management interface of Cisco Firepower Management Center (FMC) Software could allow an unauthenticated, remote attacker to conduct a stored cross-site scripting (XSS) attack against a user of the interface of an affected device. These vulnerabilities are due to insufficient validation of user-supplied input b
nvd
CVE-2024-20372P4MEDIUMCVSS 6.1v6.2.3v6.2.3.1+89 more2024-10-23
CVE-2024-20372 [MEDIUM] CWE-79 CVE-2024-20372: A vulnerability in the web-based management interface of Cisco Firepower Management Center (FMC) Sof
A vulnerability in the web-based management interface of Cisco Firepower Management Center (FMC) Software could allow an unauthenticated, remote attacker to conduct a stored cross-site scripting (XSS) attack against a user of the interface of an affected device. This vulnerability is due to insufficient validation of user-supplied input by the web-ba
nvd
CVE-2024-20386P4MEDIUMCVSS 6.1v6.2.3v6.2.3.1+89 more2024-10-23
CVE-2024-20386 [MEDIUM] CWE-79 CVE-2024-20386: A vulnerability in the web-based management interface of Cisco Firepower Management Center (FMC) Sof
A vulnerability in the web-based management interface of Cisco Firepower Management Center (FMC) Software could allow an unauthenticated, remote attacker to conduct a stored cross-site scripting (XSS) attack against a user of the interface of an affected device. This vulnerability is due to insufficient validation of user-supplied input by the web-ba
nvd
CVE-2024-20410P4MEDIUMCVSS 6.1v6.2.3v6.2.3.1+89 more2024-10-23
CVE-2024-20410 [MEDIUM] CWE-79 CVE-2024-20410: A vulnerability in the web-based management interface of Cisco Firepower Management Center (FMC) Sof
A vulnerability in the web-based management interface of Cisco Firepower Management Center (FMC) Software could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface of an affected device. This vulnerability is due to insufficient validation of user-supplied input by the web-based man
nvd
CVE-2024-20415P4MEDIUMCVSS 6.1v6.2.3v6.2.3.1+89 more2024-10-23
CVE-2024-20415 [MEDIUM] CWE-79 CVE-2024-20415: A vulnerability in the web-based management interface of Cisco Firepower Management Center (FMC) Sof
A vulnerability in the web-based management interface of Cisco Firepower Management Center (FMC) Software could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface of an affected device. This vulnerability is due to insufficient validation of user-supplied input by the web-based man
nvd
CVE-2024-20409P4MEDIUMCVSS 6.1v6.2.3v6.2.3.1+90 more2024-10-23
CVE-2024-20409 [MEDIUM] CWE-79 CVE-2024-20409: A vulnerability in the web-based management interface of Cisco Firepower Management Center (FMC) Sof
A vulnerability in the web-based management interface of Cisco Firepower Management Center (FMC) Software could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface of an affected device. This vulnerability is due to insufficient validation of user-supplied input by the web-based man
nvd
CVE-2025-20235P4MEDIUMCVSS 6.1v6.2.3.12v6.2.3.1+92 more2025-08-14
CVE-2025-20235 [MEDIUM] CWE-79 CVE-2025-20235: A vulnerability in the web-based management interface of Cisco Secure Firewall Management Center (FM
A vulnerability in the web-based management interface of Cisco Secure Firewall Management Center (FMC) Software could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface.
This vulnerability is due to insufficient validation of user-supplied input by the web-based management interfa
nvd
CVE-2019-1930P4MEDIUMCVSS 6.1≥ unspecified, < 6.2.3.142019-07-06
CVE-2019-1930 [MEDIUM] CWE-79 CVE-2019-1930: Multiple vulnerabilities in the RSS dashboard in the web-based management interface of Cisco Firepow
Multiple vulnerabilities in the RSS dashboard in the web-based management interface of Cisco Firepower Management Center (FMC) could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web-based management interface of an affected device. The vulnerabilities are due to insufficient validation o
nvd
CVE-2019-1931P4MEDIUMCVSS 6.1≥ unspecified, < 6.2.3.142019-07-06
CVE-2019-1931 [MEDIUM] CWE-79 CVE-2019-1931: Multiple vulnerabilities in the RSS dashboard in the web-based management interface of Cisco Firepow
Multiple vulnerabilities in the RSS dashboard in the web-based management interface of Cisco Firepower Management Center (FMC) could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web-based management interface of an affected device. The vulnerabilities are due to insufficient validation o
nvd
CVE-2020-3557P4MEDIUMCVSS 5.3vn/a2020-10-21
CVE-2020-3557 [MEDIUM] CWE-295 CVE-2020-3557: A vulnerability in the host input API daemon of Cisco Firepower Management Center (FMC) Software cou
A vulnerability in the host input API daemon of Cisco Firepower Management Center (FMC) Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. The vulnerability is due to improper certificate validation. An attacker could exploit this vulnerability by sending a crafted data stream t
nvd
CVE-2025-20218P4MEDIUMCVSS 4.9v6.2.3.12v6.2.3.1+85 more2025-08-14
CVE-2025-20218 [MEDIUM] CWE-643 CVE-2025-20218: A vulnerability in the web-based management interface of Cisco Secure Firewall Management Center (FM
A vulnerability in the web-based management interface of Cisco Secure Firewall Management Center (FMC) Software could allow an authenticated, remote attacker to retrieve sensitive information from an affected device.
This vulnerability is due to insufficient input validation. An attacker could exploit this vulnerability by sending a crafted request
nvd
CVE-2019-1671P4MEDIUMCVSS 6.1v6.0v6.1+3 more2019-02-07
CVE-2019-1671 [MEDIUM] CWE-79 CVE-2019-1671: A vulnerability in the web-based management interface of Cisco Firepower Management Center (FMC) cou
A vulnerability in the web-based management interface of Cisco Firepower Management Center (FMC) could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web-based management interface of an affected system. The vulnerability is due to insufficient validation of user-supplied input by the web-
nvd
CVE-2020-3553P4MEDIUMCVSS 6.1vn/a2020-10-21
CVE-2020-3553 [MEDIUM] CWE-79 CVE-2020-3553: Multiple vulnerabilities in the web-based management interface of Cisco Firepower Management Center
Multiple vulnerabilities in the web-based management interface of Cisco Firepower Management Center (FMC) Software could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface. These vulnerabilities are due to insufficient validation of user-supplied input by the web-based management inte
nvd
CVE-2020-3515P4MEDIUMCVSS 6.1vn/a2020-10-21
CVE-2020-3515 [MEDIUM] CWE-79 CVE-2020-3515: Multiple vulnerabilities in the web-based management interface of Cisco Firepower Management Center
Multiple vulnerabilities in the web-based management interface of Cisco Firepower Management Center (FMC) Software could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface. These vulnerabilities are due to insufficient validation of user-supplied input by the web-based management inte
nvd
CVE-2021-1126P4MEDIUMCVSS 5.5vn/a2021-01-13
CVE-2021-1126 [MEDIUM] CWE-256 CVE-2021-1126: A vulnerability in the storage of proxy server credentials of Cisco Firepower Management Center (FMC
A vulnerability in the storage of proxy server credentials of Cisco Firepower Management Center (FMC) could allow an authenticated, local attacker to view credentials for a configured proxy server. The vulnerability is due to clear-text storage and weak permissions of related configuration files. An attacker could exploit this vulnerability by accessi
nvd
CVE-2024-20298P4MEDIUMCVSS 5.4v7.3.0v7.3.1+5 more2024-10-23
CVE-2024-20298 [MEDIUM] CWE-79 CVE-2024-20298: A vulnerability in the web-based management interface of Cisco Firepower Management Center (FMC) Sof
A vulnerability in the web-based management interface of Cisco Firepower Management Center (FMC) Software could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface of an affected device. This vulnerability is due to insufficient validation of user-supplied input by the web-based manag
nvd