Cisco Firepower Management Center Virtual Appliance vulnerabilities

8 known vulnerabilities affecting cisco/firepower_management_center_virtual_appliance.

Total CVEs
8
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
HIGH5MEDIUM3

Vulnerabilities

Page 1 of 1
CVE-2021-34781HIGHCVSS 7.5v6.3.0v6.4.0+6 more2021-10-27
CVE-2021-34781 [HIGH] CWE-119 CVE-2021-34781: A vulnerability in the processing of SSH connections for multi-instance deployments of Cisco Firepow A vulnerability in the processing of SSH connections for multi-instance deployments of Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on the affected device. This vulnerability is due to a lack of proper error handling when an SSH session fails to be establishe
nvd
CVE-2021-34755HIGHCVSS 7.8v6.1.0v6.2.0+10 more2021-10-27
CVE-2021-34755 [HIGH] CWE-20 CVE-2021-34755: Multiple vulnerabilities in the CLI of Cisco Firepower Threat Defense (FTD) Software could allow an Multiple vulnerabilities in the CLI of Cisco Firepower Threat Defense (FTD) Software could allow an authenticated, local attacker to execute arbitrary commands with root privileges. For more information about these vulnerabilities, see the Details section of this advisory.
nvd
CVE-2021-34762HIGHCVSS 8.1v6.2.3v6.4.0+8 more2021-10-27
CVE-2021-34762 [HIGH] CWE-26 CVE-2021-34762: A vulnerability in the web-based management interface of Cisco Firepower Management Center (FMC) Sof A vulnerability in the web-based management interface of Cisco Firepower Management Center (FMC) Software could allow an authenticated, remote attacker to perform a directory traversal attack on an affected device. The attacker would require valid device credentials. The vulnerability is due to insufficient input validation of the HTTPS URL by the web-
nvd
CVE-2021-34756HIGHCVSS 7.8v6.1.0v6.2.0+10 more2021-10-27
CVE-2021-34756 [HIGH] CWE-20 CVE-2021-34756: Multiple vulnerabilities in the CLI of Cisco Firepower Threat Defense (FTD) Software could allow an Multiple vulnerabilities in the CLI of Cisco Firepower Threat Defense (FTD) Software could allow an authenticated, local attacker to execute arbitrary commands with root privileges. For more information about these vulnerabilities, see the Details section of this advisory.
nvd
CVE-2021-34761MEDIUMCVSS 6.0v6.2.3v6.4.0+4 more2021-10-27
CVE-2021-34761 [MEDIUM] CWE-73 CVE-2021-34761: A vulnerability in Cisco Firepower Threat Defense (FTD) Software could allow an authenticated, local A vulnerability in Cisco Firepower Threat Defense (FTD) Software could allow an authenticated, local attacker to overwrite or append arbitrary data to system files using root-level privileges. The attacker must have administrative credentials on the device. This vulnerability is due to incomplete validation of user input for a specific CLI command. A
nvd
CVE-2021-34764MEDIUMCVSS 6.1v6.1.0v6.2.0+9 more2021-10-27
CVE-2021-34764 [MEDIUM] CWE-601 CVE-2021-34764: Multiple vulnerabilities in the web-based management interface of Cisco Firepower Management Center Multiple vulnerabilities in the web-based management interface of Cisco Firepower Management Center (FMC) Software could allow an attacker to execute a cross-site scripting (XSS) attack or an open redirect attack. For more information about these vulnerabilities, see the Details section of this advisory.
nvd
CVE-2021-34763MEDIUMCVSS 4.8v6.1.0v6.2.0+9 more2021-10-27
CVE-2021-34763 [MEDIUM] CWE-601 CVE-2021-34763: Multiple vulnerabilities in the web-based management interface of Cisco Firepower Management Center Multiple vulnerabilities in the web-based management interface of Cisco Firepower Management Center (FMC) Software could allow an attacker to execute a cross-site scripting (XSS) attack or an open redirect attack. For more information about these vulnerabilities, see the Details section of this advisory.
nvd
CVE-2018-0365HIGHCVSS 8.8v6.0.1v6.1.0+4 more2018-06-21
CVE-2018-0365 [HIGH] CWE-352 CVE-2018-0365: A vulnerability in the web-based management interface of Cisco Firepower Management Center could all A vulnerability in the web-based management interface of Cisco Firepower Management Center could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack and perform arbitrary actions on an affected device. The vulnerability is due to insufficient CSRF protections for the web-based management interface of the affec
nvd