Cisco Secure Firewall Management Center vulnerabilities
178 known vulnerabilities affecting cisco/secure_firewall_management_center.
Total CVEs
178
CISA KEV
1
actively exploited
Public exploits
6
Exploited in wild
1
Severity breakdown
CRITICAL6HIGH56MEDIUM116
Vulnerabilities
Page 3 of 9
CVE-2020-3499P3HIGHCVSS 8.6v6.2.3v6.3.0+2 more2020-10-21
CVE-2020-3499 [HIGH] CWE-399 CVE-2020-3499: A vulnerability in the licensing service of Cisco Firepower Management Center (FMC) Software could a
A vulnerability in the licensing service of Cisco Firepower Management Center (FMC) Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition.The vulnerability is due to improper handling of system resource values by the affected system. An attacker could exploit this vulnerability by sending malicious request
nvd
CVE-2020-3549P3HIGHCVSS 8.1fixed in 6.6.12020-10-21
CVE-2020-3549 [HIGH] CWE-326 CVE-2020-3549: A vulnerability in the sftunnel functionality of Cisco Firepower Management Center (FMC) Software an
A vulnerability in the sftunnel functionality of Cisco Firepower Management Center (FMC) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to obtain the device registration hash. The vulnerability is due to insufficient sftunnel negotiation protection during initial device registration. An attacke
nvd
CVE-2021-1223P3HIGHCVSS 7.5v2.9.14.0v2.9.15+1 more2021-01-13
CVE-2021-1223 [HIGH] CWE-693 CVE-2021-1223: Multiple Cisco products are affected by a vulnerability in the Snort detection engine that could all
Multiple Cisco products are affected by a vulnerability in the Snort detection engine that could allow an unauthenticated, remote attacker to bypass a configured file policy for HTTP. The vulnerability is due to incorrect handling of an HTTP range header. An attacker could exploit this vulnerability by sending crafted HTTP packets through an affected de
nvd
CVE-2019-1832P3HIGHCVSS 7.5v6.2.0v6.2.0.5+4 more2019-05-16
CVE-2019-1832 [HIGH] CWE-693 CVE-2019-1832: A vulnerability in the detection engine of Cisco Firepower Threat Defense (FTD) Software could allow
A vulnerability in the detection engine of Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to bypass configured access control policies. The vulnerability is due to improper validation of ICMP packets. An attacker could exploit this vulnerability by sending crafted ICMP packets to the affected device. A succ
nvd
CVE-2022-20918P3HIGHCVSS 7.5≥ 7.0.0, < 7.0.52022-11-15
CVE-2022-20918 [HIGH] CWE-284 CVE-2022-20918: A vulnerability in the Simple Network Management Protocol (SNMP) access controls for Cisco FirePOWER
A vulnerability in the Simple Network Management Protocol (SNMP) access controls for Cisco FirePOWER Software for Adaptive Security Appliance (ASA) FirePOWER module, Cisco Firepower Management Center (FMC) Software, and Cisco Next-Generation Intrusion Prevention System (NGIPS) Software could allow an unauthenticated, remote attacker to perform an SNMP
nvd
CVE-2022-20925P3HIGHCVSS 7.2v6.7.0v6.7.0.1+13 more2022-11-15
CVE-2022-20925 [HIGH] CWE-77 CVE-2022-20925: A vulnerability in the web management interface of the Cisco Firepower Management Center (FMC) Softw
A vulnerability in the web management interface of the Cisco Firepower Management Center (FMC) Software could allow an authenticated, remote attacker to execute arbitrary commands on the underlying operating system.
The vulnerability is due to insufficient validation of user-supplied parameters for certain API endpoints. An attacker could exploit this
nvd
CVE-2017-12244P3HIGHCVSS 8.6v6.0.0v6.0.0.0+10 more2017-10-05
CVE-2017-12244 [HIGH] CWE-20 CVE-2017-12244: A vulnerability in the detection engine parsing of IPv6 packets for Cisco Firepower System Software
A vulnerability in the detection engine parsing of IPv6 packets for Cisco Firepower System Software could allow an unauthenticated, remote attacker to cause high CPU utilization or to cause a denial of service (DoS) condition because the Snort process restarts unexpectedly. The vulnerability is due to improper input validation of the fields in the IPv6
nvd
CVE-2018-0365P3HIGHCVSS 8.8v6.0.1v6.1.0+4 more2018-06-21
CVE-2018-0365 [HIGH] CWE-352 CVE-2018-0365: A vulnerability in the web-based management interface of Cisco Firepower Management Center could all
A vulnerability in the web-based management interface of Cisco Firepower Management Center could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack and perform arbitrary actions on an affected device. The vulnerability is due to insufficient CSRF protections for the web-based management interface of the affec
nvd
CVE-2021-34754P3HIGHCVSS 7.5v2.9.12v2.9.14.0+3 more2021-10-27
CVE-2021-34754 [HIGH] CWE-284 CVE-2021-34754: Multiple vulnerabilities in the payload inspection for Ethernet Industrial Protocol (ENIP) traffic f
Multiple vulnerabilities in the payload inspection for Ethernet Industrial Protocol (ENIP) traffic for Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to bypass configured rules for ENIP traffic. These vulnerabilities are due to incomplete processing during deep packet inspection for ENIP packets. An attac
nvd
CVE-2016-9193P3HIGHCVSS 7.5v6.0.0v6.0.0.0+4 more2016-12-14
CVE-2016-9193 [HIGH] CWE-20 CVE-2016-9193: A vulnerability in the malicious file detection and blocking features of Cisco Firepower Management
A vulnerability in the malicious file detection and blocking features of Cisco Firepower Management Center and Cisco FireSIGHT System Software could allow an unauthenticated, remote attacker to bypass malware detection mechanisms on an affected system. Affected Products: Cisco Firepower Management Center and FireSIGHT System Software are affected when the
nvd
CVE-2019-1970P3HIGHCVSS 7.5v6.3.0v6.4.02019-08-08
CVE-2019-1970 [HIGH] CWE-693 CVE-2019-1970: A vulnerability in the Secure Sockets Layer (SSL)/Transport Layer Security (TLS) protocol inspection
A vulnerability in the Secure Sockets Layer (SSL)/Transport Layer Security (TLS) protocol inspection engine of Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to bypass the configured file policies on an affected system. The vulnerability is due to errors when handling specific SSL/TLS messages. An attacker
nvd
CVE-2020-3312P3HIGHCVSS 7.5v6.2.3v6.2.3.10+3 more2020-05-06
CVE-2020-3312 [HIGH] CWE-284 CVE-2020-3312: A vulnerability in the application policy configuration of Cisco Firepower Threat Defense (FTD) Soft
A vulnerability in the application policy configuration of Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to gain unauthorized read access to sensitive data on an affected device. The vulnerability is due to insufficient application identification. An attacker could exploit this vulnerability by sending cra
nvd
CVE-2017-12245P3HIGHCVSS 8.6v6.0.1v6.0.1.3+7 more2017-10-05
CVE-2017-12245 [HIGH] CWE-399 CVE-2017-12245: A vulnerability in SSL traffic decryption for Cisco Firepower Threat Defense (FTD) Software could al
A vulnerability in SSL traffic decryption for Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause depletion of system memory, aka a Firepower Detection Engine SSL Decryption Memory Consumption Denial of Service vulnerability. If this memory leak persists over time, a denial of service (DoS) condition
nvd
CVE-2021-40114P3HIGHCVSS 7.5v2.9.14.0v2.9.15+2 more2021-10-27
CVE-2021-40114 [HIGH] CWE-770 CVE-2021-40114: Multiple Cisco products are affected by a vulnerability in the way the Snort detection engine proces
Multiple Cisco products are affected by a vulnerability in the way the Snort detection engine processes ICMP traffic that could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. The vulnerability is due to improper memory resource management while the Snort detection engine is processing ICMP
nvd
CVE-2023-20063P3HIGHCVSS 8.2≥ 6.2.3, ≤ 6.2.3.18≥ 6.4.0, ≤ 6.4.0.16+4 more2023-11-01
CVE-2023-20063 [HIGH] CWE-94 CVE-2023-20063: A vulnerability in the inter-device communication mechanisms between devices that are running Cisco
A vulnerability in the inter-device communication mechanisms between devices that are running Cisco Firepower Threat Defense (FTD) Software and devices that are running Cisco Firepower Management (FMC) Software could allow an authenticated, local attacker to execute arbitrary commands with root permissions on the underlying operating system of an affect
nvd
CVE-2019-1709P3HIGHCVSS 7.8v6.3.02019-05-03
CVE-2019-1709 [HIGH] CWE-78 CVE-2019-1709: A vulnerability in the CLI of Cisco Firepower Threat Defense (FTD) Software could allow an authentic
A vulnerability in the CLI of Cisco Firepower Threat Defense (FTD) Software could allow an authenticated, local attacker to perform a command injection attack. The vulnerability is due to insufficient input validation. An attacker could exploit this vulnerability by injecting commands into arguments for a specific command. A successful exploit could allo
nvd
CVE-2024-20379P3MEDIUMCVSS 6.5v7.3.0v7.3.1+2 more2024-10-23
CVE-2024-20379 [MEDIUM] CWE-36 CVE-2024-20379: A vulnerability in the web-based management interface of Cisco Secure Firewall Management Center (FM
A vulnerability in the web-based management interface of Cisco Secure Firewall Management Center (FMC) Software, formerly Firepower Management Center Software, could allow an authenticated, remote attacker to read arbitrary files from the underlying operating system.
This vulnerability exists because the web-based management interface does not proper
nvd
CVE-2018-15458P3HIGHCVSS 7.5v6.2.2v6.2.3+1 more2019-01-10
CVE-2018-15458 [HIGH] CWE-399 CVE-2018-15458: A vulnerability in the Shell Access Filter feature of Cisco Firepower Management Center (FMC), when
A vulnerability in the Shell Access Filter feature of Cisco Firepower Management Center (FMC), when used in conjunction with remote authentication, could allow an unauthenticated, remote attacker to cause high disk utilization, resulting in a denial of service (DoS) condition. The vulnerability occurs because the configuration of the Shell Access Filte
nvd
CVE-2018-0370P3HIGHCVSS 7.5v6.1.0.7v6.2.0.5+1 more2018-07-16
CVE-2018-0370 [HIGH] CWE-399 CVE-2018-0370: A vulnerability in the detection engine of Cisco Firepower System Software could allow an unauthenti
A vulnerability in the detection engine of Cisco Firepower System Software could allow an unauthenticated, remote attacker to cause one of the detection engine processes to run out of memory and thus slow down traffic processing. The vulnerability is due to improper handling of traffic when the Secure Sockets Layer (SSL) inspection policy is enabled. An
nvd
CVE-2019-1699P3HIGHCVSS 7.8fixed in 6.2.3.122019-05-03
CVE-2019-1699 [HIGH] CWE-78 CVE-2019-1699: A vulnerability in the CLI of Cisco Firepower Threat Defense (FTD) Software could allow an authentic
A vulnerability in the CLI of Cisco Firepower Threat Defense (FTD) Software could allow an authenticated, local attacker to perform a command injection attack. The vulnerability is due to insufficient input validation. An attacker could exploit this vulnerability by injecting commands into arguments for a specific command. A successful exploit could allo
nvd