Cisco Secure Firewall Management Center vulnerabilities
178 known vulnerabilities affecting cisco/secure_firewall_management_center.
Total CVEs
178
CISA KEV
1
actively exploited
Public exploits
6
Exploited in wild
1
Severity breakdown
CRITICAL6HIGH56MEDIUM116
Vulnerabilities
Page 2 of 9
CVE-2019-12683P2HIGHCVSS 8.8v6.0.0v6.1.0+3 more2019-10-02
CVE-2019-12683 [HIGH] CWE-89 CVE-2019-12683: Multiple vulnerabilities in the web-based management interface of Cisco Firepower Management Center
Multiple vulnerabilities in the web-based management interface of Cisco Firepower Management Center (FMC) Software could allow an authenticated, remote attacker to execute arbitrary SQL injections on an affected device. These vulnerabilities exist due to improper input validation. An attacker could exploit these vulnerabilities by sending crafted SQL qu
nvd
CVE-2019-12684P2HIGHCVSS 8.8v6.2.0v6.2.2+1 more2019-10-02
CVE-2019-12684 [HIGH] CWE-89 CVE-2019-12684: Multiple vulnerabilities in the web-based management interface of Cisco Firepower Management Center
Multiple vulnerabilities in the web-based management interface of Cisco Firepower Management Center (FMC) Software could allow an authenticated, remote attacker to execute arbitrary SQL injections on an affected device. These vulnerabilities exist due to improper input validation. An attacker could exploit these vulnerabilities by sending crafted SQL qu
nvd
CVE-2019-12686P2HIGHCVSS 8.8v6.2.3v6.3.02019-10-02
CVE-2019-12686 [HIGH] CWE-89 CVE-2019-12686: Multiple vulnerabilities in the web-based management interface of Cisco Firepower Management Center
Multiple vulnerabilities in the web-based management interface of Cisco Firepower Management Center (FMC) Software could allow an authenticated, remote attacker to execute arbitrary SQL injections on an affected device. These vulnerabilities exist due to improper input validation. An attacker could exploit these vulnerabilities by sending crafted SQL qu
nvd
CVE-2019-12680P2HIGHCVSS 8.8v6.2.2v6.2.32019-10-02
CVE-2019-12680 [HIGH] CWE-89 CVE-2019-12680: Multiple vulnerabilities in the web-based management interface of Cisco Firepower Management Center
Multiple vulnerabilities in the web-based management interface of Cisco Firepower Management Center (FMC) Software could allow an authenticated, remote attacker to execute arbitrary SQL injections on an affected device. These vulnerabilities exist due to improper input validation. An attacker could exploit these vulnerabilities by sending crafted SQL qu
nvd
CVE-2019-12687P2HIGHCVSS 8.8v6.2.2v6.2.32019-10-02
CVE-2019-12687 [HIGH] CWE-119 CVE-2019-12687: A vulnerability in the web UI of the Cisco Firepower Management Center (FMC) could allow an authenti
A vulnerability in the web UI of the Cisco Firepower Management Center (FMC) could allow an authenticated, remote attacker to execute arbitrary commands on an affected device. The vulnerability is due to insufficient input validation. An attacker could exploit this vulnerability by sending crafted input to the web UI. A successful exploit could allow
nvd
CVE-2019-12688P2HIGHCVSS 8.8v6.2.22019-10-02
CVE-2019-12688 [HIGH] CWE-119 CVE-2019-12688: A vulnerability in the web UI of the Cisco Firepower Management Center (FMC) could allow an authenti
A vulnerability in the web UI of the Cisco Firepower Management Center (FMC) could allow an authenticated, remote attacker to execute arbitrary commands on an affected device. The vulnerability is due to insufficient input validation. An attacker could exploit this vulnerability by sending crafted input to the web UI. A successful exploit could allow
nvd
CVE-2022-20926P2HIGHCVSS 8.8v7.0.0v7.0.0.1+9 more2022-11-15
CVE-2022-20926 [HIGH] CWE-77 CVE-2022-20926: A vulnerability in the web management interface of the Cisco Firepower Management Center (FMC) Softw
A vulnerability in the web management interface of the Cisco Firepower Management Center (FMC) Software could allow an authenticated, remote attacker to execute arbitrary commands on the underlying operating system.
The vulnerability is due to insufficient validation of user-supplied parameters for certain API endpoints. An attacker could exploit this
nvd
CVE-2025-20148P2HIGHCVSS 8.5v7.0.6v7.0.6.1+17 more2025-08-14
CVE-2025-20148 [HIGH] CWE-20 CVE-2025-20148: A vulnerability in the web-based management interface of Cisco Secure Firewall Management Center (FM
A vulnerability in the web-based management interface of Cisco Secure Firewall Management Center (FMC) Software could allow an authenticated, remote attacker to inject arbitrary HTML content into a device-generated document.
This vulnerability is due to improper validation of user-supplied data. An attacker could exploit this vulnerability by submitti
nvd
CVE-2021-34749P3HIGHCVSS 8.6v2.9.182021-08-18
CVE-2021-34749 [HIGH] CWE-200 CVE-2021-34749: A vulnerability in Server Name Identification (SNI) request filtering of Cisco Web Security Applianc
A vulnerability in Server Name Identification (SNI) request filtering of Cisco Web Security Appliance (WSA), Cisco Firepower Threat Defense (FTD), and the Snort detection engine could allow an unauthenticated, remote attacker to bypass filtering technology on an affected device and exfiltrate data from a compromised host. This vulnerability is due to
nvd
CVE-2020-3550P3HIGHCVSS 8.1≤ 6.0.1≥ 6.3.0, < 6.3.0.6+3 more2020-10-21
CVE-2020-3550 [HIGH] CWE-22 CVE-2020-3550: A vulnerability in the sfmgr daemon of Cisco Firepower Management Center (FMC) Software and Cisco Fi
A vulnerability in the sfmgr daemon of Cisco Firepower Management Center (FMC) Software and Cisco Firepower Threat Defense (FTD) Software could allow an authenticated, remote attacker to perform directory traversal and access directories outside the restricted path. The vulnerability is due to insufficient input validation. An attacker could exploit this
nvd
CVE-2018-0383P3HIGHCVSS 8.6v6.2.2.1v6.2.3+1 more2018-07-16
CVE-2018-0383 [HIGH] CWE-693 CVE-2018-0383: A vulnerability in the detection engine of Cisco FireSIGHT System Software could allow an unauthenti
A vulnerability in the detection engine of Cisco FireSIGHT System Software could allow an unauthenticated, remote attacker to bypass a file policy that is configured to block the transfer of files to an affected system via FTP. The vulnerability exists because the affected software incorrectly handles FTP control connections. An attacker could exploit t
nvd
CVE-2016-1458P3HIGHCVSS 8.8v4.10.3v5.2.0+3 more2016-08-18
CVE-2016-1458 [HIGH] CWE-264 CVE-2016-1458: The web-based GUI in Cisco Firepower Management Center 4.x and 5.x before 5.3.0.3, 5.3.1.x before 5.
The web-based GUI in Cisco Firepower Management Center 4.x and 5.x before 5.3.0.3, 5.3.1.x before 5.3.1.2, and 5.4.x before 5.4.0.1 and Cisco Adaptive Security Appliance (ASA) Software on 5500-X devices with FirePOWER Services 4.x and 5.x before 5.3.0.3, 5.3.1.x before 5.3.1.2, and 5.4.x before 5.4.0.1 allows remote authenticated users to increase user-
nvd
CVE-2019-15992P3HIGHCVSS 7.2fixed in 6.2.3.16≥ 6.3.0, < 6.3.0.6+2 more2020-09-23
CVE-2019-15992 [HIGH] CWE-119 CVE-2019-15992: A vulnerability in the implementation of the Lua interpreter integrated in Cisco Adaptive Security A
A vulnerability in the implementation of the Lua interpreter integrated in Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an authenticated, remote attacker to execute arbitrary code with root privileges on the underlying Linux operating system of an affected device. The vulnerability is d
nvd
CVE-2020-3318P3CRITICALCVSS 9.8v2.0.3v2.1.0+11 more2020-05-06
CVE-2020-3318 [CRITICAL] CWE-798 CVE-2020-3318: Multiple vulnerabilities in Cisco Firepower Management Center (FMC) Software and Cisco Firepower Use
Multiple vulnerabilities in Cisco Firepower Management Center (FMC) Software and Cisco Firepower User Agent Software could allow an attacker to access a sensitive part of an affected system with a high-privileged account. For more information about these vulnerabilities, see the Details section of this advisory.
nvd
CVE-2020-3302P3HIGHCVSS 8.1fixed in 6.2.2.22020-05-06
CVE-2020-3302 [HIGH] CWE-20 CVE-2020-3302: A vulnerability in the web UI of Cisco Firepower Management Center (FMC) Software could allow an aut
A vulnerability in the web UI of Cisco Firepower Management Center (FMC) Software could allow an authenticated, remote attacker to overwrite files on the file system of an affected device. The vulnerability is due to insufficient input validation. An attacker could exploit this vulnerability by uploading a crafted file to the web UI on an affected device
nvd
CVE-2020-3410P3HIGHCVSS 8.1v6.6.0v6.6.0.12020-10-21
CVE-2020-3410 [HIGH] CWE-287 CVE-2020-3410: A vulnerability in the Common Access Card (CAC) authentication feature of Cisco Firepower Management
A vulnerability in the Common Access Card (CAC) authentication feature of Cisco Firepower Management Center (FMC) Software could allow an unauthenticated, remote attacker to bypass authentication and access the FMC system. The attacker must have a valid CAC to initiate the access attempt. The vulnerability is due to incorrect session invalidation during
nvd
CVE-2024-20374P3HIGHCVSS 7.2v6.7.0v6.7.0.1+40 more2024-10-23
CVE-2024-20374 [HIGH] CWE-269 CVE-2024-20374: A vulnerability in the web-based management interface of Cisco Secure Firewall Management Center (FM
A vulnerability in the web-based management interface of Cisco Secure Firewall Management Center (FMC) Software, formerly Firepower Management Center Software, could allow an authenticated, remote attacker with Administrator-level privileges to execute arbitrary commands on the underlying operating system.
This vulnerability is due to insufficient inp
nvd
CVE-2016-6368P3HIGHCVSS 8.6v6.0.0v6.0.0.0+2 more2017-04-20
CVE-2016-6368 [HIGH] CWE-399 CVE-2016-6368: A vulnerability in the detection engine parsing of Pragmatic General Multicast (PGM) protocol packet
A vulnerability in the detection engine parsing of Pragmatic General Multicast (PGM) protocol packets for Cisco Firepower System Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition due to the Snort process unexpectedly restarting. The vulnerability is due to improper input validation of the fields in the
nvd
CVE-2019-12690P3HIGHCVSS 7.2fixed in 6.3.0.5≥ 6.4.0, < 6.4.0.42019-10-02
CVE-2019-12690 [HIGH] CWE-78 CVE-2019-12690: A vulnerability in the web UI of the Cisco Firepower Management Center (FMC) could allow an authenti
A vulnerability in the web UI of the Cisco Firepower Management Center (FMC) could allow an authenticated, remote attacker to inject arbitrary commands that are executed with the privileges of the root user of the underlying operating system. The vulnerability is due to insufficient validation of user-supplied input to the web UI. An attacker could exp
nvd
CVE-2018-0233P3HIGHCVSS 8.6v5.4.0v6.0.0+3 more2018-04-19
CVE-2018-0233 [HIGH] CWE-400 CVE-2018-0233: A vulnerability in the Secure Sockets Layer (SSL) packet reassembly functionality of the detection e
A vulnerability in the Secure Sockets Layer (SSL) packet reassembly functionality of the detection engine in Cisco Firepower System Software could allow an unauthenticated, remote attacker to cause the detection engine to consume excessive system memory on an affected device, which could cause a denial of service (DoS) condition. The vulnerability is du
nvd