Cisco Secure Firewall Management Center vulnerabilities
178 known vulnerabilities affecting cisco/secure_firewall_management_center.
Total CVEs
178
CISA KEV
1
actively exploited
Public exploits
6
Exploited in wild
1
Severity breakdown
CRITICAL6HIGH56MEDIUM116
Vulnerabilities
Page 4 of 9
CVE-2016-6419P3HIGHCVSS 7.5v4.10.3v5.2.0+3 more2016-10-05
CVE-2016-6419 [HIGH] CWE-89 CVE-2016-6419: SQL injection vulnerability in Cisco Firepower Management Center 4.10.3 through 5.4.0 allows remote
SQL injection vulnerability in Cisco Firepower Management Center 4.10.3 through 5.4.0 allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors, aka Bug ID CSCur25485.
nvd
CVE-2024-20340P3MEDIUMCVSS 6.5v7.0.0v7.0.0.1+37 more2024-10-23
CVE-2024-20340 [MEDIUM] CWE-89 CVE-2024-20340: A vulnerability in the web-based management interface of Cisco Secure Firewall Management Center (FM
A vulnerability in the web-based management interface of Cisco Secure Firewall Management Center (FMC) Software, formerly Firepower Management Center Software, could allow an authenticated, remote attacker to perform an SQL injection attack against an affected device. To exploit this vulnerability, an attacker must have a valid account on the device
nvd
CVE-2021-40116P3HIGHCVSS 7.5v3.1.0.12021-10-27
CVE-2021-40116 [HIGH] CWE-241 CVE-2021-40116: Multiple Cisco products are affected by a vulnerability in Snort rules that could allow an unauthent
Multiple Cisco products are affected by a vulnerability in Snort rules that could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device.The vulnerability is due to improper handling of the Block with Reset or Interactive Block with Reset actions if a rule is configured without proper constraints.
nvd
CVE-2023-20114P3MEDIUMCVSS 6.5≥ 6.2.3, ≤ 6.2.3.18≥ 6.4.0, ≤ 6.4.0.16+5 more2023-11-01
CVE-2023-20114 [MEDIUM] CWE-73 CVE-2023-20114: A vulnerability in the file download feature of Cisco Firepower Management Center (FMC) Software cou
A vulnerability in the file download feature of Cisco Firepower Management Center (FMC) Software could allow an authenticated, remote attacker to download arbitrary files from an affected system. This vulnerability is due to a lack of input sanitation. An attacker could exploit this vulnerability by sending a crafted HTTPS request. A successful explo
nvd
CVE-2018-0385P3HIGHCVSS 7.5v5.4.0v6.0.0+5 more2018-07-16
CVE-2018-0385 [HIGH] CWE-399 CVE-2018-0385: A vulnerability in the detection engine parsing of Security Socket Layer (SSL) protocol packets for
A vulnerability in the detection engine parsing of Security Socket Layer (SSL) protocol packets for Cisco Firepower System Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition due to the Snort process unexpectedly restarting. The vulnerability is due to improper input handling of the SSL traffic. An attack
nvd
CVE-2016-6439P3HIGHCVSS 7.5v5.3.0v5.3.0.2+22 more2016-10-27
CVE-2016-6439 [HIGH] CWE-399 CVE-2016-6439: A vulnerability in the detection engine reassembly of HTTP packets for Cisco Firepower System Softwa
A vulnerability in the detection engine reassembly of HTTP packets for Cisco Firepower System Software before 6.0.1 could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition due to the Snort process unexpectedly restarting. The vulnerability is due to improper handling of an HTTP packet stream. An attacker could exploi
nvd
CVE-2022-20854P3HIGHCVSS 7.5≥ 6.1.0, ≤ 6.1.0.7≥ 6.2.0, ≤ 6.2.0.6+23 more2022-11-15
CVE-2022-20854 [HIGH] CWE-400 CVE-2022-20854: A vulnerability in the processing of SSH connections of Cisco Firepower Management Center (FMC) and
A vulnerability in the processing of SSH connections of Cisco Firepower Management Center (FMC) and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device.
This vulnerability is due to improper error handling when an SSH session fails to be establi
nvd
CVE-2024-20482P3MEDIUMCVSS 6.5v7.2.0v7.2.0.1+17 more2024-10-23
CVE-2024-20482 [MEDIUM] CWE-863 CVE-2024-20482: A vulnerability in the web-based management interface of Cisco Secure Firewall Management Center (FM
A vulnerability in the web-based management interface of Cisco Secure Firewall Management Center (FMC) Software, formerly Firepower Management Center Software, could allow an authenticated, remote attacker to elevate privileges on an affected device. To exploit this vulnerability, an attacker must have a valid account on the device that is configure
nvd
CVE-2025-20301P3MEDIUMCVSS 6.5v6.2.3v6.2.3.1+91 more2025-08-14
CVE-2025-20301 [MEDIUM] CWE-862 CVE-2025-20301: A vulnerability in the web-based management interface of Cisco Secure FMC Software could allow an au
A vulnerability in the web-based management interface of Cisco Secure FMC Software could allow an authenticated, low-privileged, remote attacker to access troubleshoot files for a different domain.
This vulnerability is due to missing authorization checks. An attacker could exploit this vulnerability by directly accessing a troubleshoot file for a
nvd
CVE-2024-20471P3MEDIUMCVSS 6.5v6.2.3v6.2.3.1+89 more2024-10-23
CVE-2024-20471 [MEDIUM] CWE-89 CVE-2024-20471: A vulnerability in the web-based management interface of Cisco Secure Firewall Management Center (FM
A vulnerability in the web-based management interface of Cisco Secure Firewall Management Center (FMC) Software could allow an authenticated, remote attacker to conduct SQL injection attacks on an affected system.
This vulnerability exists because the web-based management interface does not validate user input adequately. An attacker could exploit th
nvd
CVE-2024-20473P3MEDIUMCVSS 6.5v7.3.0v7.3.1+5 more2024-10-23
CVE-2024-20473 [MEDIUM] CWE-89 CVE-2024-20473: A vulnerability in the web-based management interface of Cisco Secure Firewall Management Center (FM
A vulnerability in the web-based management interface of Cisco Secure Firewall Management Center (FMC) Software could allow an authenticated, remote attacker to conduct SQL injection attacks on an affected system.
This vulnerability exists because the web-based management interface does not validate user input adequately. An attacker could exploit t
nvd
CVE-2024-20472P3MEDIUMCVSS 6.5v7.3.0v7.3.1+5 more2024-10-23
CVE-2024-20472 [MEDIUM] CWE-89 CVE-2024-20472: A vulnerability in the web-based management interface of Cisco Secure Firewall Management Center (FM
A vulnerability in the web-based management interface of Cisco Secure Firewall Management Center (FMC) Software could allow an authenticated, remote attacker to conduct SQL injection attacks on an affected system.
This vulnerability exists because the web-based management interface does not validate user input adequately. An attacker could exploit t
nvd
CVE-2022-20744P3MEDIUMCVSS 6.5fixed in 7.1.02022-05-03
CVE-2022-20744 [MEDIUM] CWE-807 CVE-2022-20744: A vulnerability in the input protection mechanisms of Cisco Firepower Management Center (FMC) Softwa
A vulnerability in the input protection mechanisms of Cisco Firepower Management Center (FMC) Software could allow an authenticated, remote attacker to view data without proper authorization. This vulnerability exists because of a protection mechanism that relies on the existence or values of a specific input. An attacker could exploit this vulnerab
nvd
CVE-2018-0278P3MEDIUMCVSS 6.5v6.1.0v6.2.0+3 more2018-05-02
CVE-2018-0278 [MEDIUM] CWE-200 CVE-2018-0278: A vulnerability in the management console of Cisco Firepower System Software could allow an unauthen
A vulnerability in the management console of Cisco Firepower System Software could allow an unauthenticated, remote attacker to access sensitive data about the system. The vulnerability is due to improper cross-origin domain protections for the WebSocket protocol. An attacker could exploit this vulnerability by convincing a user to visit a malicious w
nvd
CVE-2024-20275P3MEDIUMCVSS 6.1v7.1.0v7.1.0.1+20 more2024-10-23
CVE-2024-20275 [MEDIUM] CWE-78 CVE-2024-20275: A vulnerability in the cluster backup feature of Cisco Secure Firewall Management Center (FMC) Softw
A vulnerability in the cluster backup feature of Cisco Secure Firewall Management Center (FMC) Software, formerly Firepower Management Center Software, could allow an authenticated, remote attacker to execute arbitrary commands on the underlying operating system.
This vulnerability is due to insufficient validation of user data that is supplied thro
nvd
CVE-2019-1696P3HIGHCVSS 7.4v2.9.8v2.9.9+4 more2019-05-03
CVE-2019-1696 [HIGH] CWE-400 CVE-2019-1696: Multiple vulnerabilities in the Server Message Block (SMB) Protocol preprocessor detection engine fo
Multiple vulnerabilities in the Server Message Block (SMB) Protocol preprocessor detection engine for Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, adjacent or remote attacker to cause a denial of service (DoS) condition. For more information about these vulnerabilities, see the Details section of this advisory.
nvd
CVE-2023-20155P3MEDIUMCVSS 6.5≥ 6.2.3, ≤ 6.2.3.18≥ 6.4.0, ≤ 6.4.0.16+5 more2023-11-01
CVE-2023-20155 [MEDIUM] CWE-770 CVE-2023-20155: A vulnerability in a logging API in Cisco Firepower Management Center (FMC) Software could allow an
A vulnerability in a logging API in Cisco Firepower Management Center (FMC) Software could allow an unauthenticated, remote attacker to cause the device to become unresponsive or trigger an unexpected reload. This vulnerability could also allow an attacker with valid user credentials, but not Administrator privileges, to view a system log file that t
nvd
CVE-2019-12700P3MEDIUMCVSS 6.5≤ 6.1.0≥ 6.2.0, < 6.2.3.14+1 more2019-10-02
CVE-2019-12700 [MEDIUM] CWE-400 CVE-2019-12700: A vulnerability in the configuration of the Pluggable Authentication Module (PAM) used in Cisco Fire
A vulnerability in the configuration of the Pluggable Authentication Module (PAM) used in Cisco Firepower Threat Defense (FTD) Software, Cisco Firepower Management Center (FMC) Software, and Cisco FXOS Software could allow an authenticated, remote attacker to cause a denial of service (DoS) condition. The vulnerability is due to improper resource ma
nvd
CVE-2018-0384P3MEDIUMCVSS 5.8v6.0.0v6.1.0+3 more2018-07-16
CVE-2018-0384 [MEDIUM] CWE-693 CVE-2018-0384: A vulnerability in the detection engine of Cisco FireSIGHT System Software could allow an unauthenti
A vulnerability in the detection engine of Cisco FireSIGHT System Software could allow an unauthenticated, remote attacker to bypass a URL-based access control policy that is configured to block traffic for an affected system. The vulnerability exists because the affected software incorrectly handles TCP packets that are received out of order when a T
nvd
CVE-2018-0333P4MEDIUMCVSS 5.8v6.2.22018-06-07
CVE-2018-0333 [MEDIUM] CWE-693 CVE-2018-0333: A vulnerability in the VPN configuration management of Cisco FireSIGHT System Software could allow a
A vulnerability in the VPN configuration management of Cisco FireSIGHT System Software could allow an unauthenticated, remote attacker to bypass VPN security due to unintended side effects of dynamic configuration changes that could allow an attacker to bypass configured policies. The vulnerability is due to incorrect management of the configured inte
nvd