cbcvebase.

Cisco Secure Firewall Management Center vulnerabilities

178 known vulnerabilities affecting cisco/secure_firewall_management_center.

Total CVEs
178
CISA KEV
1
actively exploited
Public exploits
6
Exploited in wild
1
Severity breakdown
CRITICAL6HIGH56MEDIUM116

Vulnerabilities

Page 1 of 9
CVE-2026-20131P1CRITICALCVSS 10.0KEVRansomwarev6.4.0.13v6.4.0.14+69 more2026-03-04
CVE-2026-20131 [CRITICAL] CWE-502 CVE-2026-20131: A vulnerability in the web-based management interface of Cisco Secure Firewall Management Center (FM A vulnerability in the web-based management interface of Cisco Secure Firewall Management Center (FMC) Software could allow an unauthenticated, remote attacker to execute arbitrary Java code as root on an affected device. This vulnerability is due to insecure deserialization of a user-supplied Java byte stream. An attacker could exploit this vuln
nvd
CVE-2016-6433P2HIGHCVSS 8.8PoCv5.2.0v5.3.0+18 more2016-10-06
CVE-2016-6433 [HIGH] CWE-20 CVE-2016-6433: The Threat Management Console in Cisco Firepower Management Center 5.2.0 through 6.0.1 allows remote The Threat Management Console in Cisco Firepower Management Center 5.2.0 through 6.0.1 allows remote authenticated users to execute arbitrary commands via crafted web-application parameters, aka Bug ID CSCva30872.
nvd
CVE-2023-20048P2CRITICALCVSS 9.9PoC≥ 6.2.3, ≤ 6.2.3.18≥ 6.4.0, ≤ 6.4.0.16+6 more2023-11-01
CVE-2023-20048 [CRITICAL] CWE-269 CVE-2023-20048: A vulnerability in the web services interface of Cisco Firepower Management Center (FMC) Software co A vulnerability in the web services interface of Cisco Firepower Management Center (FMC) Software could allow an authenticated, remote attacker to execute certain unauthorized configuration commands on a Firepower Threat Defense (FTD) device that is managed by the FMC Software. This vulnerability is due to insufficient authorization of configurati
nvd
CVE-2025-20265P1CRITICALCVSS 10.0v7.0.7v7.7.02025-08-14
CVE-2025-20265 [CRITICAL] CWE-74 CVE-2025-20265: A vulnerability in the RADIUS subsystem implementation of Cisco Secure Firewall Management Center (F A vulnerability in the RADIUS subsystem implementation of Cisco Secure Firewall Management Center (FMC) Software could allow an unauthenticated, remote attacker to inject arbitrary shell commands that are executed by the device. This vulnerability is due to a lack of proper handling of user input during the authentication phase. An attacker could
nvd
CVE-2016-6435P3MEDIUMCVSS 6.5PoCv6.0.12016-10-06
CVE-2016-6435 [MEDIUM] CWE-200 CVE-2016-6435: The web console in Cisco Firepower Management Center 6.0.1 allows remote authenticated users to read The web console in Cisco Firepower Management Center 6.0.1 allows remote authenticated users to read arbitrary files via crafted parameters, aka Bug ID CSCva30376.
nvd
CVE-2019-1978P3MEDIUMCVSS 5.8PoC≥ 2.9.12, ≤ 2.9.12.15≥ 2.9.13, ≤ 2.9.13.6+3 more2019-11-05
CVE-2019-1978 [MEDIUM] CWE-264 CVE-2019-1978: A vulnerability in the stream reassembly component of Cisco Firepower Threat Defense Software, Cisco A vulnerability in the stream reassembly component of Cisco Firepower Threat Defense Software, Cisco FirePOWER Services Software for ASA, and Cisco Firepower Management Center Software could allow an unauthenticated, remote attacker to bypass filtering protections. The vulnerability is due to improper reassembly of traffic streams. An attacker could e
nvd
CVE-2024-20424P2CRITICALCVSS 9.9v6.2.3v6.2.3.1+90 more2024-10-23
CVE-2024-20424 [CRITICAL] CWE-78 CVE-2024-20424: A vulnerability in the web-based management interface of Cisco Secure Firewall Management Center (FM A vulnerability in the web-based management interface of Cisco Secure Firewall Management Center (FMC) Software, formerly Firepower Management Center Software, could allow an authenticated, remote attacker to execute arbitrary commands on the underlying operating system as root. This vulnerability is due to insufficient input validation of certain
nvd
CVE-2019-16028P2CRITICALCVSS 9.8fixed in 6.2.3.16≥ 6.3.0, < 6.3.0.6+2 more2020-09-23
CVE-2019-16028 [CRITICAL] CWE-287 CVE-2019-16028: A vulnerability in the web-based management interface of Cisco Firepower Management Center (FMC) cou A vulnerability in the web-based management interface of Cisco Firepower Management Center (FMC) could allow an unauthenticated, remote attacker to bypass authentication and execute arbitrary actions with administrative privileges on an affected device. The vulnerability is due to improper handling of Lightweight Directory Access Protocol (LDAP) a
nvd
CVE-2022-20743P2HIGHCVSS 8.8fixed in 6.4.0.15≥ 6.5.0, < 6.6.5.2+2 more2022-05-03
CVE-2022-20743 [HIGH] CWE-434 CVE-2022-20743: A vulnerability in the web management interface of Cisco Firepower Management Center (FMC) Software A vulnerability in the web management interface of Cisco Firepower Management Center (FMC) Software could allow an authenticated, remote attacker to bypass security protections and upload malicious files to the affected system. This vulnerability is due to improper validation of files uploaded to the web management interface of Cisco FMC Software. An a
nvd
CVE-2016-1457P2HIGHCVSS 8.8v4.10.3.9v5.2.0+3 more2016-08-18
CVE-2016-1457 [HIGH] CWE-264 CVE-2016-1457: The web-based GUI in Cisco Firepower Management Center 4.x and 5.x before 5.3.1.2 and 5.4.x before 5 The web-based GUI in Cisco Firepower Management Center 4.x and 5.x before 5.3.1.2 and 5.4.x before 5.4.0.1 and Cisco Adaptive Security Appliance (ASA) Software on 5500-X devices with FirePOWER Services 4.x and 5.x before 5.3.1.2 and 5.4.x before 5.4.0.1 allows remote authenticated users to execute arbitrary commands as root via crafted HTTP requests, ak
nvd
CVE-2019-1642P3MEDIUMCVSS 6.1PoCv6.2.3v6.3.02019-01-23
CVE-2019-1642 [MEDIUM] CWE-79 CVE-2019-1642: A vulnerability in the web-based management interface of Cisco Firepower Management Center (FMC) sof A vulnerability in the web-based management interface of Cisco Firepower Management Center (FMC) software could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web-based management interface of the affected software. The vulnerability is due to insufficient validation of user-supplied input
nvd
CVE-2023-20220P2HIGHCVSS 8.8≥ 6.2.3, ≤ 6.2.3.18≥ 6.4.0, ≤ 6.4.0.16+6 more2023-11-01
CVE-2023-20220 [HIGH] CWE-22 CVE-2023-20220: Multiple vulnerabilities in the web-based management interface of Cisco Firepower Management Center Multiple vulnerabilities in the web-based management interface of Cisco Firepower Management Center (FMC) Software could allow an authenticated, remote attacker to execute arbitrary commands on the underlying operating system. To exploit these vulnerabilities, the attacker must have valid device credentials, but does not need Administrator privileges. T
nvd
CVE-2023-20219P2HIGHCVSS 8.8≥ 6.2.3, ≤ 6.2.3.18≥ 6.4.0, ≤ 6.4.0.16+5 more2023-11-01
CVE-2023-20219 [HIGH] CWE-78 CVE-2023-20219: Multiple vulnerabilities in the web management interface of Cisco Firepower Management Center (FMC) Multiple vulnerabilities in the web management interface of Cisco Firepower Management Center (FMC) Software could allow an authenticated, remote attacker to execute arbitrary commands on the underlying operating system. The attacker would need valid device credentials but does not require administrator privileges to exploit this vulnerability. These vu
nvd
CVE-2024-20360P2HIGHCVSS 8.8v7.0.0v7.0.0.1+25 more2024-05-22
CVE-2024-20360 [HIGH] CWE-89 CVE-2024-20360: A vulnerability in the web-based management interface of Cisco Firepower Management Center (FMC) Sof A vulnerability in the web-based management interface of Cisco Firepower Management Center (FMC) Software could allow an authenticated, remote attacker to conduct SQL injection attacks on an affected system. This vulnerability exists because the web-based management interface does not adequately validate user input. An attacker could exploit this vulne
nvd
CVE-2016-6434P3HIGHCVSS 7.8PoCv6.0.12016-10-06
CVE-2016-6434 [HIGH] CWE-287 CVE-2016-6434: Cisco Firepower Management Center 6.0.1 has hardcoded database credentials, which allows local users Cisco Firepower Management Center 6.0.1 has hardcoded database credentials, which allows local users to obtain sensitive information by leveraging CLI access, aka Bug ID CSCva30370.
nvd
CVE-2019-12689P2HIGHCVSS 8.8fixed in 6.2.2.22019-10-02
CVE-2019-12689 [HIGH] CWE-20 CVE-2019-12689: A vulnerability in the web-based management interface of Cisco Firepower Management Center (FMC) Sof A vulnerability in the web-based management interface of Cisco Firepower Management Center (FMC) Software could allow an authenticated, remote attacker to execute arbitrary code on the underlying operating system of an affected device. The vulnerability is due to insufficient input validation. An attacker could exploit this vulnerability by sending mal
nvd
CVE-2019-12679P2HIGHCVSS 8.8v6.2.22019-10-02
CVE-2019-12679 [HIGH] CWE-89 CVE-2019-12679: Multiple vulnerabilities in the web-based management interface of Cisco Firepower Management Center Multiple vulnerabilities in the web-based management interface of Cisco Firepower Management Center (FMC) Software could allow an authenticated, remote attacker to execute arbitrary SQL injections on an affected device. These vulnerabilities exist due to improper input validation. An attacker could exploit these vulnerabilities by sending crafted SQL qu
nvd
CVE-2019-12681P2HIGHCVSS 8.8v6.0.0v6.2.0+2 more2019-10-02
CVE-2019-12681 [HIGH] CWE-89 CVE-2019-12681: Multiple vulnerabilities in the web-based management interface of Cisco Firepower Management Center Multiple vulnerabilities in the web-based management interface of Cisco Firepower Management Center (FMC) Software could allow an authenticated, remote attacker to execute arbitrary SQL injections on an affected device. These vulnerabilities exist due to improper input validation. An attacker could exploit these vulnerabilities by sending crafted SQL qu
nvd
CVE-2019-12685P2HIGHCVSS 8.8v6.2.22019-10-02
CVE-2019-12685 [HIGH] CWE-89 CVE-2019-12685: Multiple vulnerabilities in the web-based management interface of Cisco Firepower Management Center Multiple vulnerabilities in the web-based management interface of Cisco Firepower Management Center (FMC) Software could allow an authenticated, remote attacker to execute arbitrary SQL injections on an affected device. These vulnerabilities exist due to improper input validation. An attacker could exploit these vulnerabilities by sending crafted SQL qu
nvd
CVE-2019-12682P2HIGHCVSS 8.8v6.2.22019-10-02
CVE-2019-12682 [HIGH] CWE-89 CVE-2019-12682: Multiple vulnerabilities in the web-based management interface of Cisco Firepower Management Center Multiple vulnerabilities in the web-based management interface of Cisco Firepower Management Center (FMC) Software could allow an authenticated, remote attacker to execute arbitrary SQL injections on an affected device. These vulnerabilities exist due to improper input validation. An attacker could exploit these vulnerabilities by sending crafted SQL qu
nvd