Cisco Secure Firewall Management Center vulnerabilities
178 known vulnerabilities affecting cisco/secure_firewall_management_center.
Total CVEs
178
CISA KEV
1
actively exploited
Public exploits
6
Exploited in wild
0
Severity breakdown
CRITICAL6HIGH56MEDIUM116
Vulnerabilities
Page 4 of 9
CVE-2022-20935MEDIUMCVSS 4.8v6.1.0v6.1.0.1+90 more2022-11-15
CVE-2022-20935 [MEDIUM] CWE-79 CVE-2022-20935: Multiple vulnerabilities in the web-based management interface of Cisco Firepower Management Center
Multiple vulnerabilities in the web-based management interface of Cisco Firepower Management Center (FMC) Software could allow an authenticated, remote attacker to conduct a stored cross-site scripting (XSS) attack against a user of the interface of an affected device.
These vulnerabilities are due to insufficient validation of user-supplied input by
nvd
CVE-2022-20905MEDIUMCVSS 4.8v6.1.0v6.1.0.1+90 more2022-11-15
CVE-2022-20905 [MEDIUM] CWE-79 CVE-2022-20905: Multiple vulnerabilities in the web-based management interface of Cisco Firepower Management Center
Multiple vulnerabilities in the web-based management interface of Cisco Firepower Management Center (FMC) Software could allow an authenticated, remote attacker to conduct a stored cross-site scripting (XSS) attack against a user of the interface of an affected device.
These vulnerabilities are due to insufficient validation of user-supplied input by
nvd
CVE-2022-20834MEDIUMCVSS 4.8v6.1.0v6.1.0.1+90 more2022-11-15
CVE-2022-20834 [MEDIUM] CWE-79 CVE-2022-20834: Multiple vulnerabilities in the web-based management interface of Cisco Firepower Management Center
Multiple vulnerabilities in the web-based management interface of Cisco Firepower Management Center (FMC) Software could allow an authenticated, remote attacker to conduct a stored cross-site scripting (XSS) attack against a user of the interface of an affected device.
These vulnerabilities are due to insufficient validation of user-supplied input by
nvd
CVE-2022-20836MEDIUMCVSS 4.8v6.1.0v6.1.0.1+90 more2022-11-15
CVE-2022-20836 [MEDIUM] CWE-79 CVE-2022-20836: Multiple vulnerabilities in the web-based management interface of Cisco Firepower Management Center
Multiple vulnerabilities in the web-based management interface of Cisco Firepower Management Center (FMC) Software could allow an authenticated, remote attacker to conduct a stored cross-site scripting (XSS) attack against a user of the interface of an affected device.
These vulnerabilities are due to insufficient validation of user-supplied input by
nvd
CVE-2022-20838MEDIUMCVSS 4.8v6.1.0v6.1.0.1+90 more2022-11-15
CVE-2022-20838 [MEDIUM] CWE-79 CVE-2022-20838: Multiple vulnerabilities in the web-based management interface of Cisco Firepower Management Center
Multiple vulnerabilities in the web-based management interface of Cisco Firepower Management Center (FMC) Software could allow an authenticated, remote attacker to conduct a stored cross-site scripting (XSS) attack against a user of the interface of an affected device.
These vulnerabilities are due to insufficient validation of user-supplied input by
nvd
CVE-2022-20936MEDIUMCVSS 4.8v6.1.0v6.1.0.1+90 more2022-11-15
CVE-2022-20936 [MEDIUM] CWE-79 CVE-2022-20936: Multiple vulnerabilities in the web-based management interface of Cisco Firepower Management Center
Multiple vulnerabilities in the web-based management interface of Cisco Firepower Management Center (FMC) Software could allow an authenticated, remote attacker to conduct a stored cross-site scripting (XSS) attack against a user of the interface of an affected device.
These vulnerabilities are due to insufficient validation of user-supplied input by
nvd
CVE-2022-20872MEDIUMCVSS 4.8v6.1.0v6.1.0.1+90 more2022-11-15
CVE-2022-20872 [MEDIUM] CWE-79 CVE-2022-20872: Multiple vulnerabilities in the web-based management interface of Cisco Firepower Management Center
Multiple vulnerabilities in the web-based management interface of Cisco Firepower Management Center (FMC) Software could allow an authenticated, remote attacker to conduct a stored cross-site scripting (XSS) attack against a user of the interface of an affected device.
These vulnerabilities are due to insufficient validation of user-supplied input by
nvd
CVE-2022-20743HIGHCVSS 8.8fixed in 6.4.0.15≥ 6.5.0, < 6.6.5.2+2 more2022-05-03
CVE-2022-20743 [HIGH] CWE-434 CVE-2022-20743: A vulnerability in the web management interface of Cisco Firepower Management Center (FMC) Software
A vulnerability in the web management interface of Cisco Firepower Management Center (FMC) Software could allow an authenticated, remote attacker to bypass security protections and upload malicious files to the affected system. This vulnerability is due to improper validation of files uploaded to the web management interface of Cisco FMC Software. An a
nvd
CVE-2022-20628MEDIUMCVSS 5.4fixed in 6.4.0.15≥ 6.5.0, < 6.6.5.2+1 more2022-05-03
CVE-2022-20628 [MEDIUM] CWE-79 CVE-2022-20628: Multiple vulnerabilities in the web-based management interface of Cisco Firepower Management Center
Multiple vulnerabilities in the web-based management interface of Cisco Firepower Management Center (FMC) Software could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface. These vulnerabilities are due to insufficient validation of user-supplied input by the web-based management inte
nvd
CVE-2022-20744MEDIUMCVSS 6.5fixed in 7.1.02022-05-03
CVE-2022-20744 [MEDIUM] CWE-807 CVE-2022-20744: A vulnerability in the input protection mechanisms of Cisco Firepower Management Center (FMC) Softwa
A vulnerability in the input protection mechanisms of Cisco Firepower Management Center (FMC) Software could allow an authenticated, remote attacker to view data without proper authorization. This vulnerability exists because of a protection mechanism that relies on the existence or values of a specific input. An attacker could exploit this vulnerab
nvd
CVE-2022-20740MEDIUMCVSS 6.1fixed in 6.6.5.2≥ 6.7.0, < 7.0.2+1 more2022-05-03
CVE-2022-20740 [MEDIUM] CWE-80 CVE-2022-20740: A vulnerability in the web-based management interface of Cisco Firepower Management Center (FMC) Sof
A vulnerability in the web-based management interface of Cisco Firepower Management Center (FMC) Software could allow an unauthenticated, remote attacker to conduct a cross-site scripting attack. This vulnerability is due to improper validation of user-supplied input to the web-based management interface. An attacker could exploit this vulnerability
nvd
CVE-2022-20629MEDIUMCVSS 5.4fixed in 6.4.0.15≥ 6.5.0, < 6.6.5.2+1 more2022-05-03
CVE-2022-20629 [MEDIUM] CWE-79 CVE-2022-20629: Multiple vulnerabilities in the web-based management interface of Cisco Firepower Management Center
Multiple vulnerabilities in the web-based management interface of Cisco Firepower Management Center (FMC) Software could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface. These vulnerabilities are due to insufficient validation of user-supplied input by the web-based management inte
nvd
CVE-2022-20627MEDIUMCVSS 5.4fixed in 6.4.0.15≥ 6.5.0, < 6.6.5.2+1 more2022-05-03
CVE-2022-20627 [MEDIUM] CWE-79 CVE-2022-20627: Multiple vulnerabilities in the web-based management interface of Cisco Firepower Management Center
Multiple vulnerabilities in the web-based management interface of Cisco Firepower Management Center (FMC) Software could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface. These vulnerabilities are due to insufficient validation of user-supplied input by the web-based management inte
nvd
CVE-2021-34754HIGHCVSS 7.5v2.9.12v2.9.14.0+3 more2021-10-27
CVE-2021-34754 [HIGH] CWE-284 CVE-2021-34754: Multiple vulnerabilities in the payload inspection for Ethernet Industrial Protocol (ENIP) traffic f
Multiple vulnerabilities in the payload inspection for Ethernet Industrial Protocol (ENIP) traffic for Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to bypass configured rules for ENIP traffic. These vulnerabilities are due to incomplete processing during deep packet inspection for ENIP packets. An attac
nvd
CVE-2021-40114HIGHCVSS 7.5v2.9.14.0v2.9.15+2 more2021-10-27
CVE-2021-40114 [HIGH] CWE-770 CVE-2021-40114: Multiple Cisco products are affected by a vulnerability in the way the Snort detection engine proces
Multiple Cisco products are affected by a vulnerability in the way the Snort detection engine processes ICMP traffic that could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. The vulnerability is due to improper memory resource management while the Snort detection engine is processing ICMP
nvd
CVE-2021-40116HIGHCVSS 7.5v3.1.0.12021-10-27
CVE-2021-40116 [HIGH] CWE-241 CVE-2021-40116: Multiple Cisco products are affected by a vulnerability in Snort rules that could allow an unauthent
Multiple Cisco products are affected by a vulnerability in Snort rules that could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device.The vulnerability is due to improper handling of the Block with Reset or Interactive Block with Reset actions if a rule is configured without proper constraints.
nvd
CVE-2021-34749HIGHCVSS 8.6v2.9.182021-08-18
CVE-2021-34749 [HIGH] CWE-200 CVE-2021-34749: A vulnerability in Server Name Identification (SNI) request filtering of Cisco Web Security Applianc
A vulnerability in Server Name Identification (SNI) request filtering of Cisco Web Security Appliance (WSA), Cisco Firepower Threat Defense (FTD), and the Snort detection engine could allow an unauthenticated, remote attacker to bypass filtering technology on an affected device and exfiltrate data from a compromised host. This vulnerability is due to
nvd
CVE-2021-1455MEDIUMCVSS 4.8≤ 6.4.0.11≥ 6.5.0, < 6.6.3+1 more2021-04-29
CVE-2021-1455 [MEDIUM] CWE-79 CVE-2021-1455: Multiple vulnerabilities in the web-based management interface of Cisco Firepower Management Center
Multiple vulnerabilities in the web-based management interface of Cisco Firepower Management Center (FMC) Software could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface. These vulnerabilities are due to insufficient validation of user-supplied input by the web-based management inte
nvd
CVE-2021-1456MEDIUMCVSS 4.8≤ 6.4.0.11≥ 6.5.0, < 6.6.3+1 more2021-04-29
CVE-2021-1456 [MEDIUM] CWE-79 CVE-2021-1456: Multiple vulnerabilities in the web-based management interface of Cisco Firepower Management Center
Multiple vulnerabilities in the web-based management interface of Cisco Firepower Management Center (FMC) Software could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface. These vulnerabilities are due to insufficient validation of user-supplied input by the web-based management inte
nvd
CVE-2021-1458MEDIUMCVSS 4.8≤ 6.4.0.11≥ 6.5.0, < 6.6.3+1 more2021-04-29
CVE-2021-1458 [MEDIUM] CWE-79 CVE-2021-1458: Multiple vulnerabilities in the web-based management interface of Cisco Firepower Management Center
Multiple vulnerabilities in the web-based management interface of Cisco Firepower Management Center (FMC) Software could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface. These vulnerabilities are due to insufficient validation of user-supplied input by the web-based management inte
nvd