Cisco Secure Firewall Management Center vulnerabilities

8 known vulnerabilities affecting cisco/cisco_secure_firewall_management_center.

Total CVEs
8
CISA KEV
1
actively exploited
Public exploits
1
Exploited in wild
0
Severity breakdown
CRITICAL2HIGH1MEDIUM5

Vulnerabilities

Page 1 of 1
CVE-2026-20131CRITICALCVSS 10.0KEVv7.0.0v7.0.0.1+68 more2026-03-04
CVE-2026-20131 [CRITICAL] CWE-502 CVE-2026-20131: A vulnerability in the web-based management interface of Cisco Secure Firewall Management Center (FM A vulnerability in the web-based management interface of Cisco Secure Firewall Management Center (FMC) Software could allow an unauthenticated, remote attacker to execute arbitrary Java code as root on an affected device. This vulnerability is due to insecure deserialization of a user-supplied Java byte stream. An attacker could exploit this vuln
cvelistv5nvd
CVE-2026-20079CRITICALCVSS 10.0PoCv7.0.0v7.0.0.1+59 more2026-03-04
CVE-2026-20079 [CRITICAL] CWE-288 CVE-2026-20079: A vulnerability in the web interface of Cisco Secure Firewall Management Center (FMC) Software could A vulnerability in the web interface of Cisco Secure Firewall Management Center (FMC) Software could allow an unauthenticated, remote attacker to bypass authentication and execute script files on an affected device to obtain root access to the underlying operating system. This vulnerability is due to an improper system process that is created at b
cvelistv5nvd
CVE-2026-20002HIGHCVSS 8.1v6.4.0v6.4.0.1+77 more2026-03-04
CVE-2026-20002 [HIGH] CWE-89 CVE-2026-20002: A vulnerability in the web-based management interface of Cisco Secure FMC Software could allow an au A vulnerability in the web-based management interface of Cisco Secure FMC Software could allow an authenticated, remote attacker to conduct SQL injection attacks on an affected system. This vulnerability is due to inadequate validation of user-supplied input. An attacker could exploit this vulnerability by sending crafted requests to an affected device
cvelistv5nvd
CVE-2026-20001MEDIUMCVSS 6.5v7.0.0v7.0.0.1+54 more2026-03-04
CVE-2026-20001 [MEDIUM] CWE-89 CVE-2026-20001: A vulnerability in the REST API of Cisco Secure FMC Software could allow an authenticated, remote at A vulnerability in the REST API of Cisco Secure FMC Software could allow an authenticated, remote attacker to conduct SQL injection attacks on an affected system. This vulnerability is due to inadequate validation of user-supplied input. An attacker could exploit this vulnerability by sending crafted requests to an affected device. A successful expl
cvelistv5nvd
CVE-2026-20044MEDIUMCVSS 6.0v6.4.0.6v6.4.0.7+76 more2026-03-04
CVE-2026-20044 [MEDIUM] CWE-269 CVE-2026-20044: A vulnerability in the lockdown mechanism of Cisco Secure Firewall Management Center (FMC) Software A vulnerability in the lockdown mechanism of Cisco Secure Firewall Management Center (FMC) Software could allow an authenticated, local attacker to perform arbitrary commands as root. This vulnerability is due to insufficient restrictions on remediation modules while in lockdown mode. An attacker could exploit this vulnerability by sending crafted i
cvelistv5nvd
CVE-2026-20003MEDIUMCVSS 4.9v7.0.0v7.0.0.1+58 more2026-03-04
CVE-2026-20003 [MEDIUM] CWE-89 CVE-2026-20003: A vulnerability in the REST API of Cisco Secure FMC Software could allow an authenticated, remote at A vulnerability in the REST API of Cisco Secure FMC Software could allow an authenticated, remote attacker to conduct SQL injection attacks on an affected system. This vulnerability is due to inadequate validation of user-supplied input. An attacker could exploit this vulnerability by sending crafted requests to an affected device. A successful explo
cvelistv5nvd
CVE-2026-20018MEDIUMCVSS 5.9v7.0.0v7.0.0.1+57 more2026-03-04
CVE-2026-20018 [MEDIUM] CWE-27 CVE-2026-20018: A vulnerability in the sftunnel functionality of Cisco Secure Firewall Management Center (FMC) Softw A vulnerability in the sftunnel functionality of Cisco Secure Firewall Management Center (FMC) Software and Cisco Secure Firewall Threat Defense (FTD) Software could allow an authenticated, remote attacker with administrative privileges to write arbitrary files as root on the underlying operating system. This vulnerability is due to insufficient val
cvelistv5nvd
CVE-2024-20340MEDIUMCVSS 6.5v7.0.0v7.0.0.1+50 more2024-10-23
CVE-2024-20340 [MEDIUM] CWE-89 CVE-2024-20340: A vulnerability in the web-based management interface of Cisco Secure Firewall Management Center (FM A vulnerability in the web-based management interface of Cisco Secure Firewall Management Center (FMC) Software, formerly Firepower Management Center Software, could allow an authenticated, remote attacker to perform an SQL injection attack against an affected device. To exploit this vulnerability, an attacker must have a valid account on the device
cvelistv5nvd