cbcvebase.

Cisco Secure Firewall Management Center vulnerabilities

178 known vulnerabilities affecting cisco/secure_firewall_management_center.

Total CVEs
178
CISA KEV
1
actively exploited
Public exploits
6
Exploited in wild
1
Severity breakdown
CRITICAL6HIGH56MEDIUM116

Vulnerabilities

Page 5 of 9
CVE-2019-1833P4MEDIUMCVSS 5.8v6.1.0v6.2.0+3 more2019-05-16
CVE-2019-1833 [MEDIUM] CWE-693 CVE-2019-1833: A vulnerability in the Secure Sockets Layer (SSL)/Transport Layer Security (TLS) protocol parser of A vulnerability in the Secure Sockets Layer (SSL)/Transport Layer Security (TLS) protocol parser of Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to bypass configured policies. The vulnerability is due to improper parsing of specific attributes in a TLS packet header. An attacker could exploit this vulner
nvd
CVE-2021-1236P4MEDIUMCVSS 5.3v2.9.14.0v2.9.14.14+3 more2021-01-13
CVE-2021-1236 [MEDIUM] CWE-670 CVE-2021-1236: Multiple Cisco products are affected by a vulnerability in the Snort application detection engine th Multiple Cisco products are affected by a vulnerability in the Snort application detection engine that could allow an unauthenticated, remote attacker to bypass the configured policies on an affected system. The vulnerability is due to a flaw in the detection algorithm. An attacker could exploit this vulnerability by sending crafted packets that would
nvd
CVE-2024-20361P4MEDIUMCVSS 5.8v7.1.0v7.1.0.1+10 more2024-05-22
CVE-2024-20361 [MEDIUM] CWE-264 CVE-2024-20361: A vulnerability in the Object Groups for Access Control Lists (ACLs) feature of Cisco Firepower Mana A vulnerability in the Object Groups for Access Control Lists (ACLs) feature of Cisco Firepower Management Center (FMC) Software could allow an unauthenticated, remote attacker to bypass configured access controls on managed devices that are running Cisco Firepower Threat Defense (FTD) Software. This vulnerability is due to the incorrect deployment
nvd
CVE-2018-15397P4MEDIUMCVSS 6.8v6.2.22018-10-05
CVE-2018-15397 [MEDIUM] CWE-320 CVE-2018-15397: A vulnerability in the implementation of Traffic Flow Confidentiality (TFC) over IPsec functionality A vulnerability in the implementation of Traffic Flow Confidentiality (TFC) over IPsec functionality in Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause an affected device to restart unexpectedly, resulting in a denial of service (DoS) conditio
nvd
CVE-2017-6673P4MEDIUMCVSS 6.5v6.1.0.2v6.2.02017-06-13
CVE-2017-6673 [MEDIUM] CWE-200 CVE-2017-6673: A vulnerability in Cisco Firepower Management Center could allow an authenticated, remote attacker t A vulnerability in Cisco Firepower Management Center could allow an authenticated, remote attacker to obtain user information. An attacker could use this information to perform reconnaissance. More Information: CSCvc10894. Known Affected Releases: 6.1.0.2 6.2.0. Known Fixed Releases: 6.2.0.
nvd
CVE-2016-1413P4MEDIUMCVSS 6.5v5.4.0v5.4.0.2+8 more2016-05-28
CVE-2016-1413 [MEDIUM] CWE-94 CVE-2016-1413: The web interface in Cisco Firepower Management Center 5.4.0 through 6.0.0.1 allows remote authentic The web interface in Cisco Firepower Management Center 5.4.0 through 6.0.0.1 allows remote authenticated users to modify pages by placing crafted code in a parameter value, aka Bug ID CSCuy76517.
nvd
CVE-2017-12300P4MEDIUMCVSS 5.8v2.9.9v2.9.10+2 more2017-11-16
CVE-2017-12300 [MEDIUM] CWE-20 CVE-2017-12300: A vulnerability in the SNORT detection engine of Cisco Firepower System Software could allow an unau A vulnerability in the SNORT detection engine of Cisco Firepower System Software could allow an unauthenticated, remote attacker to bypass a file policy that is configured to block the Server Message Block Version 2 (SMB2) protocol. The vulnerability is due to the incorrect detection of an SMB2 file when the detection is based on the length of the fi
nvd
CVE-2019-1981P4MEDIUMCVSS 5.8≥ 2.9.12, ≤ 2.9.12.15≥ 2.9.13, ≤ 2.9.13.6+3 more2019-11-05
CVE-2019-1981 [MEDIUM] CWE-264 CVE-2019-1981: A vulnerability in the normalization functionality of Cisco Firepower Threat Defense Software, Cisco A vulnerability in the normalization functionality of Cisco Firepower Threat Defense Software, Cisco FirePOWER Services Software for ASA, and Cisco Firepower Management Center Software could allow an unauthenticated, remote attacker to bypass filtering protections. The vulnerability is due to insufficient normalization of a text-based payload. An atta
nvd
CVE-2020-3315P4MEDIUMCVSS 5.3v2.9.14.4v2.9.15+1 more2020-05-06
CVE-2020-3315 [MEDIUM] CWE-693 CVE-2020-3315: Multiple Cisco products are affected by a vulnerability in the Snort detection engine that could all Multiple Cisco products are affected by a vulnerability in the Snort detection engine that could allow an unauthenticated, remote attacker to bypass the configured file policies on an affected system. The vulnerability is due to errors in how the Snort detection engine handles specific HTTP responses. An attacker could exploit this vulnerability by se
nvd
CVE-2021-1224P4MEDIUMCVSS 5.3v2.9.14.0v2.9.15+4 more2021-01-13
CVE-2021-1224 [MEDIUM] CWE-693 CVE-2021-1224: Multiple Cisco products are affected by a vulnerability with TCP Fast Open (TFO) when used in conjun Multiple Cisco products are affected by a vulnerability with TCP Fast Open (TFO) when used in conjunction with the Snort detection engine that could allow an unauthenticated, remote attacker to bypass a configured file policy for HTTP. The vulnerability is due to incorrect detection of the HTTP payload if it is contained at least partially within the
nvd
CVE-2024-20388P4MEDIUMCVSS 5.3v6.2.3v6.2.3.1+75 more2024-10-23
CVE-2024-20388 [MEDIUM] CWE-202 CVE-2024-20388: A vulnerability in the password change feature of Cisco Firepower Management Center (FMC) software c A vulnerability in the password change feature of Cisco Firepower Management Center (FMC) software could allow an unauthenticated, remote attacker to determine valid user names on an affected device. This vulnerability is due to improper authentication of password update responses. An attacker could exploit this vulnerability by forcing a password r
nvd
CVE-2020-3514P4MEDIUMCVSS 6.7fixed in 6.6.12020-10-21
CVE-2020-3514 [MEDIUM] CWE-216 CVE-2020-3514: A vulnerability in the multi-instance feature of Cisco Firepower Threat Defense (FTD) Software could A vulnerability in the multi-instance feature of Cisco Firepower Threat Defense (FTD) Software could allow an authenticated, local attacker to escape the container for their Cisco FTD instance and execute commands with root privileges in the host namespace. The attacker must have valid credentials on the device.The vulnerability exists because a confi
nvd
CVE-2017-3809P4MEDIUMCVSS 5.8v6.1.0v6.2.02017-02-03
CVE-2017-3809 [MEDIUM] CWE-20 CVE-2017-3809: A vulnerability in the Policy deployment module of the Cisco Firepower Management Center (FMC) could A vulnerability in the Policy deployment module of the Cisco Firepower Management Center (FMC) could allow an unauthenticated, remote attacker to prevent deployment of a complete and accurate rule base. More Information: CSCvb95281. Known Affected Releases: 6.1.0 6.2.0. Known Fixed Releases: 6.1.0.1 6.2.0.
nvd
CVE-2017-3814P4MEDIUMCVSS 5.8v5.3.0v5.4.0+3 more2017-02-03
CVE-2017-3814 [MEDIUM] CWE-20 CVE-2017-3814: A vulnerability in Cisco Firepower System Software could allow an unauthenticated, remote attacker t A vulnerability in Cisco Firepower System Software could allow an unauthenticated, remote attacker to maliciously bypass the appliance's ability to block certain web content, aka a URL Bypass. More Information: CSCvb93980. Known Affected Releases: 5.3.0 5.4.0 6.0.0 6.0.1 6.1.0.
nvd
CVE-2019-12691P4MEDIUMCVSS 4.9fixed in 6.2.32019-10-02
CVE-2019-12691 [MEDIUM] CWE-22 CVE-2019-12691: A vulnerability in the web-based management interface of Cisco Firepower Management Center (FMC) Sof A vulnerability in the web-based management interface of Cisco Firepower Management Center (FMC) Software could allow an authenticated, remote attacker to perform a directory traversal attack on an affected device. The vulnerability is due to insufficient input validation by the web-based management interface. An attacker could exploit this vulnerabi
nvd
CVE-2025-20306P4MEDIUMCVSS 4.9v6.2.3v6.2.3.1+93 more2025-08-14
CVE-2025-20306 [MEDIUM] CWE-77 CVE-2025-20306: A vulnerability in the web-based management interface of Cisco Secure Firewall Management Center (FM A vulnerability in the web-based management interface of Cisco Secure Firewall Management Center (FMC) Software could allow an authenticated, remote attacker with Administrator-level privileges to execute arbitrary commands on the underlying operating system. This vulnerability is due to insufficient input validation of certain HTTP request paramete
nvd
CVE-2019-1982P4MEDIUMCVSS 5.3v2.9.13v2.9.14.0+1 more2019-11-05
CVE-2019-1982 [MEDIUM] CWE-264 CVE-2019-1982: A vulnerability in the HTTP traffic filtering component of Cisco Firepower Threat Defense Software, A vulnerability in the HTTP traffic filtering component of Cisco Firepower Threat Defense Software, Cisco FirePOWER Services Software for ASA, and Cisco Firepower Management Center Software could allow an unauthenticated, remote attacker to bypass filtering protections. The vulnerability is due to improper handling of HTTP requests, including those com
nvd
CVE-2020-3307P4MEDIUMCVSS 5.3v6.2.2v6.2.3+3 more2020-05-06
CVE-2020-3307 [MEDIUM] CWE-20 CVE-2020-3307: A vulnerability in the web UI of Cisco Firepower Management Center (FMC) Software could allow an una A vulnerability in the web UI of Cisco Firepower Management Center (FMC) Software could allow an unauthenticated, remote attacker to write arbitrary entries to the log file on an affected device. The vulnerability is due to insufficient input validation. An attacker could exploit this vulnerability by sending a crafted HTTP request to an affected devic
nvd
CVE-2024-20274P4MEDIUMCVSS 5.5v6.2.3v6.2.3.1+84 more2024-10-23
CVE-2024-20274 [MEDIUM] CWE-20 CVE-2024-20274: A vulnerability in the web-based management interface of Cisco Secure Firewall Management Center (FM A vulnerability in the web-based management interface of Cisco Secure Firewall Management Center (FMC) Software, formerly Firepower Management Center Software, could allow an authenticated, remote attacker to inject arbitrary HTML content into a device-generated document. This vulnerability is due to improper validation of user-supplied data. An att
nvd
CVE-2022-20941P4MEDIUMCVSS 5.3v6.1.0v6.1.0.1+91 more2022-11-15
CVE-2022-20941 [MEDIUM] CWE-334 CVE-2022-20941: A vulnerability in the web-based management interface of Cisco Firepower Management Center (FMC) Sof A vulnerability in the web-based management interface of Cisco Firepower Management Center (FMC) Software could allow an unauthenticated, remote attacker to access sensitive information. This vulnerability is due to missing authorization for certain resources in the web-based management interface together with insufficient entropy in these resource
nvd
Cisco Secure Firewall Management Center vulnerabilities | cvebase