Cisco Firepower Management Center vulnerabilities
135 known vulnerabilities affecting cisco/cisco_firepower_management_center.
Total CVEs
135
CISA KEV
0
Public exploits
2
Exploited in wild
0
Severity breakdown
CRITICAL5HIGH31MEDIUM99
Vulnerabilities
Page 4 of 7
CVE-2022-20932MEDIUMCVSS 4.8v6.2.3v6.2.3.1+55 more2022-11-15
CVE-2022-20932 [MEDIUM] CWE-79 CVE-2022-20932: Multiple vulnerabilities in the web-based management interface of Cisco Firepower Management Center
Multiple vulnerabilities in the web-based management interface of Cisco Firepower Management Center (FMC) Software could allow an authenticated, remote attacker to conduct a stored cross-site scripting (XSS) attack against a user of the interface of an affected device.
These vulnerabilities are due to insufficient validation of user-supplied input by
cvelistv5nvd
CVE-2022-20831MEDIUMCVSS 4.8v6.2.3v6.2.3.1+59 more2022-11-15
CVE-2022-20831 [MEDIUM] CWE-79 CVE-2022-20831: Multiple vulnerabilities in the web-based management interface of Cisco Firepower Management Center
Multiple vulnerabilities in the web-based management interface of Cisco Firepower Management Center (FMC) Software could allow an authenticated, remote attacker to conduct a stored cross-site scripting (XSS) attack against a user of the interface of an affected device.
These vulnerabilities are due to insufficient validation of user-supplied input by
cvelistv5nvd
CVE-2022-20839MEDIUMCVSS 4.8v6.2.3v6.2.3.1+59 more2022-11-15
CVE-2022-20839 [MEDIUM] CWE-79 CVE-2022-20839: Multiple vulnerabilities in the web-based management interface of Cisco Firepower Management Center
Multiple vulnerabilities in the web-based management interface of Cisco Firepower Management Center (FMC) Software could allow an authenticated, remote attacker to conduct a stored cross-site scripting (XSS) attack against a user of the interface of an affected device.
These vulnerabilities are due to insufficient validation of user-supplied input by
cvelistv5nvd
CVE-2022-20834MEDIUMCVSS 4.8v6.2.3v6.2.3.1+56 more2022-11-15
CVE-2022-20834 [MEDIUM] CWE-79 CVE-2022-20834: Multiple vulnerabilities in the web-based management interface of Cisco Firepower Management Center
Multiple vulnerabilities in the web-based management interface of Cisco Firepower Management Center (FMC) Software could allow an authenticated, remote attacker to conduct a stored cross-site scripting (XSS) attack against a user of the interface of an affected device.
These vulnerabilities are due to insufficient validation of user-supplied input by
cvelistv5nvd
CVE-2022-20838MEDIUMCVSS 4.8v6.2.3v6.2.3.1+59 more2022-11-15
CVE-2022-20838 [MEDIUM] CWE-79 CVE-2022-20838: Multiple vulnerabilities in the web-based management interface of Cisco Firepower Management Center
Multiple vulnerabilities in the web-based management interface of Cisco Firepower Management Center (FMC) Software could allow an authenticated, remote attacker to conduct a stored cross-site scripting (XSS) attack against a user of the interface of an affected device.
These vulnerabilities are due to insufficient validation of user-supplied input by
cvelistv5nvd
CVE-2022-20935MEDIUMCVSS 4.8v7.1.0v7.1.0.1+3 more2022-11-15
CVE-2022-20935 [MEDIUM] CWE-79 CVE-2022-20935: Multiple vulnerabilities in the web-based management interface of Cisco Firepower Management Center
Multiple vulnerabilities in the web-based management interface of Cisco Firepower Management Center (FMC) Software could allow an authenticated, remote attacker to conduct a stored cross-site scripting (XSS) attack against a user of the interface of an affected device.
These vulnerabilities are due to insufficient validation of user-supplied input by
cvelistv5nvd
CVE-2022-20872MEDIUMCVSS 4.8v6.2.3v6.2.3.1+59 more2022-11-15
CVE-2022-20872 [MEDIUM] CWE-79 CVE-2022-20872: Multiple vulnerabilities in the web-based management interface of Cisco Firepower Management Center
Multiple vulnerabilities in the web-based management interface of Cisco Firepower Management Center (FMC) Software could allow an authenticated, remote attacker to conduct a stored cross-site scripting (XSS) attack against a user of the interface of an affected device.
These vulnerabilities are due to insufficient validation of user-supplied input by
cvelistv5nvd
CVE-2022-20743HIGHCVSS 8.8vn/a2022-05-03
CVE-2022-20743 [HIGH] CWE-434 CVE-2022-20743: A vulnerability in the web management interface of Cisco Firepower Management Center (FMC) Software
A vulnerability in the web management interface of Cisco Firepower Management Center (FMC) Software could allow an authenticated, remote attacker to bypass security protections and upload malicious files to the affected system. This vulnerability is due to improper validation of files uploaded to the web management interface of Cisco FMC Software. An a
cvelistv5nvd
CVE-2022-20628MEDIUMCVSS 5.4vn/a2022-05-03
CVE-2022-20628 [MEDIUM] CWE-79 CVE-2022-20628: Multiple vulnerabilities in the web-based management interface of Cisco Firepower Management Center
Multiple vulnerabilities in the web-based management interface of Cisco Firepower Management Center (FMC) Software could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface. These vulnerabilities are due to insufficient validation of user-supplied input by the web-based management inte
cvelistv5nvd
CVE-2022-20629MEDIUMCVSS 5.4vn/a2022-05-03
CVE-2022-20629 [MEDIUM] CWE-79 CVE-2022-20629: Multiple vulnerabilities in the web-based management interface of Cisco Firepower Management Center
Multiple vulnerabilities in the web-based management interface of Cisco Firepower Management Center (FMC) Software could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface. These vulnerabilities are due to insufficient validation of user-supplied input by the web-based management inte
cvelistv5nvd
CVE-2022-20744MEDIUMCVSS 6.5vn/a2022-05-03
CVE-2022-20744 [MEDIUM] CWE-807 CVE-2022-20744: A vulnerability in the input protection mechanisms of Cisco Firepower Management Center (FMC) Softwa
A vulnerability in the input protection mechanisms of Cisco Firepower Management Center (FMC) Software could allow an authenticated, remote attacker to view data without proper authorization. This vulnerability exists because of a protection mechanism that relies on the existence or values of a specific input. An attacker could exploit this vulnerab
cvelistv5nvd
CVE-2022-20627MEDIUMCVSS 5.4vn/a2022-05-03
CVE-2022-20627 [MEDIUM] CWE-79 CVE-2022-20627: Multiple vulnerabilities in the web-based management interface of Cisco Firepower Management Center
Multiple vulnerabilities in the web-based management interface of Cisco Firepower Management Center (FMC) Software could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface. These vulnerabilities are due to insufficient validation of user-supplied input by the web-based management inte
cvelistv5nvd
CVE-2021-34762HIGHCVSS 8.1vn/a2021-10-27
CVE-2021-34762 [HIGH] CWE-26 CVE-2021-34762: A vulnerability in the web-based management interface of Cisco Firepower Management Center (FMC) Sof
A vulnerability in the web-based management interface of Cisco Firepower Management Center (FMC) Software could allow an authenticated, remote attacker to perform a directory traversal attack on an affected device. The attacker would require valid device credentials. The vulnerability is due to insufficient input validation of the HTTPS URL by the web-
cvelistv5nvd
CVE-2021-34764MEDIUMCVSS 6.1vn/a2021-10-27
CVE-2021-34764 [MEDIUM] CWE-601 CVE-2021-34764: Multiple vulnerabilities in the web-based management interface of Cisco Firepower Management Center
Multiple vulnerabilities in the web-based management interface of Cisco Firepower Management Center (FMC) Software could allow an attacker to execute a cross-site scripting (XSS) attack or an open redirect attack. For more information about these vulnerabilities, see the Details section of this advisory.
cvelistv5nvd
CVE-2021-34763MEDIUMCVSS 4.8vn/a2021-10-27
CVE-2021-34763 [MEDIUM] CWE-601 CVE-2021-34763: Multiple vulnerabilities in the web-based management interface of Cisco Firepower Management Center
Multiple vulnerabilities in the web-based management interface of Cisco Firepower Management Center (FMC) Software could allow an attacker to execute a cross-site scripting (XSS) attack or an open redirect attack. For more information about these vulnerabilities, see the Details section of this advisory.
cvelistv5nvd
CVE-2021-1455MEDIUMCVSS 4.8vn/a2021-04-29
CVE-2021-1455 [MEDIUM] CWE-79 CVE-2021-1455: Multiple vulnerabilities in the web-based management interface of Cisco Firepower Management Center
Multiple vulnerabilities in the web-based management interface of Cisco Firepower Management Center (FMC) Software could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface. These vulnerabilities are due to insufficient validation of user-supplied input by the web-based management inte
cvelistv5nvd
CVE-2021-1456MEDIUMCVSS 4.8vn/a2021-04-29
CVE-2021-1456 [MEDIUM] CWE-79 CVE-2021-1456: Multiple vulnerabilities in the web-based management interface of Cisco Firepower Management Center
Multiple vulnerabilities in the web-based management interface of Cisco Firepower Management Center (FMC) Software could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface. These vulnerabilities are due to insufficient validation of user-supplied input by the web-based management inte
cvelistv5nvd
CVE-2021-1477MEDIUMCVSS 4.3vn/a2021-04-29
CVE-2021-1477 [MEDIUM] CWE-284 CVE-2021-1477: A vulnerability in an access control mechanism of Cisco Firepower Management Center (FMC) Software c
A vulnerability in an access control mechanism of Cisco Firepower Management Center (FMC) Software could allow an authenticated, remote attacker to access services beyond the scope of their authorization. This vulnerability is due to insufficient enforcement of access control in the affected software. An attacker could exploit this vulnerability by di
cvelistv5nvd
CVE-2021-1457MEDIUMCVSS 4.8vn/a2021-04-29
CVE-2021-1457 [MEDIUM] CWE-79 CVE-2021-1457: Multiple vulnerabilities in the web-based management interface of Cisco Firepower Management Center
Multiple vulnerabilities in the web-based management interface of Cisco Firepower Management Center (FMC) Software could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface. These vulnerabilities are due to insufficient validation of user-supplied input by the web-based management inte
cvelistv5nvd
CVE-2021-1458MEDIUMCVSS 4.8vn/a2021-04-29
CVE-2021-1458 [MEDIUM] CWE-79 CVE-2021-1458: Multiple vulnerabilities in the web-based management interface of Cisco Firepower Management Center
Multiple vulnerabilities in the web-based management interface of Cisco Firepower Management Center (FMC) Software could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface. These vulnerabilities are due to insufficient validation of user-supplied input by the web-based management inte
cvelistv5nvd