cbcvebase.

Cisco Firepower Management Center vulnerabilities

128 known vulnerabilities affecting cisco/cisco_firepower_management_center.

Total CVEs
128
CISA KEV
0
Public exploits
2
Exploited in wild
0
Severity breakdown
CRITICAL5HIGH31MEDIUM92

Vulnerabilities

Page 5 of 7
CVE-2024-20264P4MEDIUMCVSS 5.4v7.1.0v7.1.0.1+13 more2024-10-23
CVE-2024-20264 [MEDIUM] CWE-79 CVE-2024-20264: A vulnerability in the web-based management interface of Cisco Firepower Management Center (FMC) Sof A vulnerability in the web-based management interface of Cisco Firepower Management Center (FMC) Software could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface of an affected device. This vulnerability is due to insufficient validation of user-supplied input by the web-based manag
nvd
CVE-2024-20269P4MEDIUMCVSS 5.4v6.2.3.12v6.2.3.1+81 more2024-10-23
CVE-2024-20269 [MEDIUM] CWE-79 CVE-2024-20269: A vulnerability in the web-based management interface of Cisco Firepower Management Center (FMC) Sof A vulnerability in the web-based management interface of Cisco Firepower Management Center (FMC) Software could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface of an affected device. This vulnerability is due to insufficient validation of user-supplied input by the web-based manag
nvd
CVE-2024-20300P4MEDIUMCVSS 5.4v6.2.3.12v6.2.3.1+83 more2024-10-23
CVE-2024-20300 [MEDIUM] CWE-79 CVE-2024-20300: A vulnerability in the web-based management interface of Cisco Firepower Management Center (FMC) Sof A vulnerability in the web-based management interface of Cisco Firepower Management Center (FMC) Software could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface of an affected device. This vulnerability is due to insufficient validation of user-supplied input by the web-based manag
nvd
CVE-2024-20364P4MEDIUMCVSS 5.4v6.7.0v6.7.0.1+40 more2024-10-23
CVE-2024-20364 [MEDIUM] CWE-79 CVE-2024-20364: A vulnerability in the web-based management interface of Cisco Firepower Management Center (FMC) Sof A vulnerability in the web-based management interface of Cisco Firepower Management Center (FMC) Software could allow an authenticated, remote attacker to conduct a stored cross-site scripting (XSS) attack against a user of the interface of an affected device. This vulnerability is due to insufficient validation of user-supplied input by the web-base
nvd
CVE-2024-20387P4MEDIUMCVSS 5.4v6.2.3.17v6.2.3.18+36 more2024-10-23
CVE-2024-20387 [MEDIUM] CWE-79 CVE-2024-20387: A vulnerability in the web-based management interface of Cisco FMC Software could allow an authentic A vulnerability in the web-based management interface of Cisco FMC Software could allow an authenticated, remote attacker to store malicious content for use in XSS attacks. This vulnerability is due to improper input sanitization in the web-based management interface of Cisco FMC Software. An attacker could exploit this vulnerability by persuading a
nvd
CVE-2024-20403P4MEDIUMCVSS 5.4v6.2.3v6.2.3.1+90 more2024-10-23
CVE-2024-20403 [MEDIUM] CWE-79 CVE-2024-20403: A vulnerability in the web-based management interface of Cisco Firepower Management Center (FMC) Sof A vulnerability in the web-based management interface of Cisco Firepower Management Center (FMC) Software could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface of an affected device. This vulnerability is due to insufficient validation of user-supplied input by the web-based manag
nvd
CVE-2020-3313P4MEDIUMCVSS 6.1vn/a2020-05-06
CVE-2020-3313 [MEDIUM] CWE-79 CVE-2020-3313: A vulnerability in the web UI of Cisco Firepower Management Center (FMC) Software could allow an una A vulnerability in the web UI of Cisco Firepower Management Center (FMC) Software could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web-based management interface of the FMC Software. The vulnerability is due to insufficient validation of user-supplied input by the web-based management
nvd
CVE-2021-34764P4MEDIUMCVSS 6.1vn/a2021-10-27
CVE-2021-34764 [MEDIUM] CWE-601 CVE-2021-34764: Multiple vulnerabilities in the web-based management interface of Cisco Firepower Management Center Multiple vulnerabilities in the web-based management interface of Cisco Firepower Management Center (FMC) Software could allow an attacker to execute a cross-site scripting (XSS) attack or an open redirect attack. For more information about these vulnerabilities, see the Details section of this advisory.
nvd
CVE-2022-20628P4MEDIUMCVSS 5.4vn/a2022-05-03
CVE-2022-20628 [MEDIUM] CWE-79 CVE-2022-20628: Multiple vulnerabilities in the web-based management interface of Cisco Firepower Management Center Multiple vulnerabilities in the web-based management interface of Cisco Firepower Management Center (FMC) Software could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface. These vulnerabilities are due to insufficient validation of user-supplied input by the web-based management inte
nvd
CVE-2022-20629P4MEDIUMCVSS 5.4vn/a2022-05-03
CVE-2022-20629 [MEDIUM] CWE-79 CVE-2022-20629: Multiple vulnerabilities in the web-based management interface of Cisco Firepower Management Center Multiple vulnerabilities in the web-based management interface of Cisco Firepower Management Center (FMC) Software could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface. These vulnerabilities are due to insufficient validation of user-supplied input by the web-based management inte
nvd
CVE-2022-20627P4MEDIUMCVSS 5.4vn/a2022-05-03
CVE-2022-20627 [MEDIUM] CWE-79 CVE-2022-20627: Multiple vulnerabilities in the web-based management interface of Cisco Firepower Management Center Multiple vulnerabilities in the web-based management interface of Cisco Firepower Management Center (FMC) Software could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface. These vulnerabilities are due to insufficient validation of user-supplied input by the web-based management inte
nvd
CVE-2024-20377P4MEDIUMCVSS 5.4v7.0.0v7.0.0.1+37 more2024-10-23
CVE-2024-20377 [MEDIUM] CWE-79 CVE-2024-20377: A vulnerability in the web-based management interface of Cisco Firepower Management Center (FMC) cou A vulnerability in the web-based management interface of Cisco Firepower Management Center (FMC) could allow an authenticated, remote attacker to conduct a stored cross-site scripting (XSS) attack against a user of the interface. This vulnerability is due to the web-based management interface not properly validating user-supplied input. An attacker c
nvd
CVE-2019-15270P4MEDIUMCVSS 5.4≥ unspecified, < n/a2019-10-16
CVE-2019-15270 [MEDIUM] CWE-79 CVE-2019-15270: A vulnerability in the web-based management interface of Cisco Firepower Management Center (FMC) cou A vulnerability in the web-based management interface of Cisco Firepower Management Center (FMC) could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web-based management interface. The vulnerability is due to insufficient validation of user-supplied input by the web-based management int
nvd
CVE-2020-3320P4MEDIUMCVSS 5.4vn/a2020-10-08
CVE-2020-3320 [MEDIUM] CWE-79 CVE-2020-3320: A vulnerability in the web-based management interface of Cisco Firepower Management Center could all A vulnerability in the web-based management interface of Cisco Firepower Management Center could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web-based management interface of an affected device. The vulnerability is due to insufficient validation of user-supplied input by the web-based ma
nvd
CVE-2021-1477P4MEDIUMCVSS 4.3vn/a2021-04-29
CVE-2021-1477 [MEDIUM] CWE-284 CVE-2021-1477: A vulnerability in an access control mechanism of Cisco Firepower Management Center (FMC) Software c A vulnerability in an access control mechanism of Cisco Firepower Management Center (FMC) Software could allow an authenticated, remote attacker to access services beyond the scope of their authorization. This vulnerability is due to insufficient enforcement of access control in the affected software. An attacker could exploit this vulnerability by di
nvd
CVE-2025-20302P4MEDIUMCVSS 4.3v6.2.3.12v6.2.3.1+90 more2025-08-14
CVE-2025-20302 [MEDIUM] CWE-862 CVE-2025-20302: A vulnerability in the web-based management interface of Cisco Secure FMC Software could allow an au A vulnerability in the web-based management interface of Cisco Secure FMC Software could allow an authenticated, low-privileged, remote attacker to retrieve a generated report from a different domain. This vulnerability is due to missing authorization checks. An attacker could exploit this vulnerability by directly accessing a generated report file
nvd
CVE-2021-34751P4MEDIUMCVSS 4.3vN/A2024-11-15
CVE-2021-34751 [MEDIUM] CWE-317 CVE-2021-34751: A vulnerability in the administrative web-based GUI configuration manager of Cisco Firepower Managem A vulnerability in the administrative web-based GUI configuration manager of Cisco Firepower Management Center (FMC) Software could allow an authenticated, remote attacker to access sensitive configuration information. The attacker would require low privilege credentials on an affected device. This vulnerability exists because of improper encryption
nvd
CVE-2021-34750P4MEDIUMCVSS 4.3vN/A2024-11-15
CVE-2021-34750 [MEDIUM] CWE-317 CVE-2021-34750: A vulnerability in the administrative web-based GUI configuration manager of Cisco Firepower Managem A vulnerability in the administrative web-based GUI configuration manager of Cisco Firepower Management Center Software could allow an authenticated, remote attacker to access sensitive configuration information. The attacker would require low privilege credentials on an affected device. This vulnerability is due to lack of proper encryption of sens
nvd
CVE-2022-20938P4MEDIUMCVSS 4.3v6.2.3v6.2.3.1+56 more2022-11-15
CVE-2022-20938 [MEDIUM] CWE-611 CVE-2022-20938: A vulnerability in the module import function of the administrative interface of Cisco Firepower Man A vulnerability in the module import function of the administrative interface of Cisco Firepower Management Center (FMC) Software could allow an authenticated, remote attacker to view sensitive information. This vulnerability is due to insufficient validation of the XML syntax when importing a module. An attacker could exploit this vulnerability by
nvd
CVE-2021-1455P4MEDIUMCVSS 4.8vn/a2021-04-29
CVE-2021-1455 [MEDIUM] CWE-79 CVE-2021-1455: Multiple vulnerabilities in the web-based management interface of Cisco Firepower Management Center Multiple vulnerabilities in the web-based management interface of Cisco Firepower Management Center (FMC) Software could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface. These vulnerabilities are due to insufficient validation of user-supplied input by the web-based management inte
nvd