Cisco Secure Firewall Management Center vulnerabilities
178 known vulnerabilities affecting cisco/secure_firewall_management_center.
Total CVEs
178
CISA KEV
1
actively exploited
Public exploits
6
Exploited in wild
1
Severity breakdown
CRITICAL6HIGH56MEDIUM116
Vulnerabilities
Page 6 of 9
CVE-2017-3885P4MEDIUMCVSS 5.9v6.0.0v6.1.0+2 more2017-04-07
CVE-2017-3885 [MEDIUM] CWE-400 CVE-2017-3885: A vulnerability in the detection engine reassembly of Secure Sockets Layer (SSL) packets for Cisco F
A vulnerability in the detection engine reassembly of Secure Sockets Layer (SSL) packets for Cisco Firepower System Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition because the Snort process consumes a high level of CPU resources. Affected Products: This vulnerability affects Cisco Firepower System
nvd
CVE-2018-0283P4MEDIUMCVSS 5.8v6.1.0v6.2.0+2 more2018-05-02
CVE-2018-0283 [MEDIUM] CWE-310 CVE-2018-0283: A vulnerability in the detection engine of Cisco Firepower System Software could allow an unauthenti
A vulnerability in the detection engine of Cisco Firepower System Software could allow an unauthenticated, remote attacker to restart an instance of the Snort detection engine on an affected device, resulting in a brief denial of service (DoS) condition. The vulnerability is due to the incorrect handling of Transport Layer Security (TLS) TCP connectio
nvd
CVE-2018-0281P4MEDIUMCVSS 5.8v6.1.0v6.2.0+3 more2018-05-02
CVE-2018-0281 [MEDIUM] CWE-310 CVE-2018-0281: A vulnerability in the detection engine of Cisco Firepower System Software could allow an unauthenti
A vulnerability in the detection engine of Cisco Firepower System Software could allow an unauthenticated, remote attacker to restart an instance of the Snort detection engine on an affected device, resulting in a brief denial of service (DoS) condition. The vulnerability is due to the incorrect handling of a Transport Layer Security (TLS) extension d
nvd
CVE-2019-1980P4MEDIUMCVSS 5.3≥ 2.9.12, ≤ 2.9.12.15≥ 2.9.13, ≤ 2.9.13.6+3 more2019-11-05
CVE-2019-1980 [MEDIUM] CWE-264 CVE-2019-1980: A vulnerability in the protocol detection component of Cisco Firepower Threat Defense Software, Cisc
A vulnerability in the protocol detection component of Cisco Firepower Threat Defense Software, Cisco FirePOWER Services Software for ASA, and Cisco Firepower Management Center Software could allow an unauthenticated, remote attacker to bypass filtering protections. The vulnerability is due to improper detection of the initial use of a protocol on a n
nvd
CVE-2020-3311P4MEDIUMCVSS 6.1fixed in 6.3.02020-05-06
CVE-2020-3311 [MEDIUM] CWE-601 CVE-2020-3311: A vulnerability in the web interface of Cisco Firepower Management Center (FMC) Software could allow
A vulnerability in the web interface of Cisco Firepower Management Center (FMC) Software could allow an unauthenticated, remote attacker to redirect a user to a malicious web page. The vulnerability is due to improper input validation of HTTP request parameters. An attacker could exploit this vulnerability by intercepting and modifying an HTTP request
nvd
CVE-2020-3558P4MEDIUMCVSS 6.1≥ 6.2.0, ≤ 6.2.3.16≥ 6.3.0, ≤ 6.3.0.5+2 more2020-10-21
CVE-2020-3558 [MEDIUM] CWE-601 CVE-2020-3558: A vulnerability in the web-based management interface of Cisco Firepower Management Center (FMC) Sof
A vulnerability in the web-based management interface of Cisco Firepower Management Center (FMC) Software could allow an unauthenticated, remote attacker to redirect a user to a malicious web page. The vulnerability is due to improper input validation of the parameters of an HTTP request. An attacker could exploit this vulnerability by intercepting an
nvd
CVE-2024-20273P4MEDIUMCVSS 6.1v6.2.3v6.2.3.1+81 more2024-10-23
CVE-2024-20273 [MEDIUM] CWE-79 CVE-2024-20273: A vulnerability in the web-based management interface of Cisco Firepower Management Center (FMC) Sof
A vulnerability in the web-based management interface of Cisco Firepower Management Center (FMC) Software could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface of an affected device. This vulnerability is due to insufficient validation of user-supplied input by the web-based man
nvd
CVE-2023-20206P4MEDIUMCVSS 6.1≥ 6.6.0, ≤ 6.6.7.1≥ 6.7.0, ≤ 6.7.0.3+4 more2023-11-01
CVE-2023-20206 [MEDIUM] CWE-79 CVE-2023-20206: Multiple vulnerabilities in the web-based management interface of Cisco Firepower Management Center
Multiple vulnerabilities in the web-based management interface of Cisco Firepower Management Center (FMC) Software could allow an unauthenticated, remote attacker to conduct a stored cross-site scripting (XSS) attack against a user of the interface of an affected device. These vulnerabilities are due to insufficient validation of user-supplied input b
nvd
CVE-2023-20005P4MEDIUMCVSS 6.1≥ 6.2.3, ≤ 6.2.3.18≥ 6.4.0, ≤ 6.4.0.16+4 more2023-11-01
CVE-2023-20005 [MEDIUM] CWE-79 CVE-2023-20005: Multiple vulnerabilities in the web-based management interface of Cisco Firepower Management Center
Multiple vulnerabilities in the web-based management interface of Cisco Firepower Management Center (FMC) Software could allow an unauthenticated, remote attacker to conduct a stored cross-site scripting (XSS) attack against a user of the interface of an affected device. These vulnerabilities are due to insufficient validation of user-supplied input b
nvd
CVE-2023-20074P4MEDIUMCVSS 6.1≥ 6.2.3, ≤ 6.2.3.18≥ 6.4.0, ≤ 6.4.0.16+5 more2023-11-01
CVE-2023-20074 [MEDIUM] CWE-79 CVE-2023-20074: Multiple vulnerabilities in the web-based management interface of Cisco Firepower Management Center
Multiple vulnerabilities in the web-based management interface of Cisco Firepower Management Center (FMC) Software could allow an unauthenticated, remote attacker to conduct a stored cross-site scripting (XSS) attack against a user of the interface of an affected device. These vulnerabilities are due to insufficient validation of user-supplied input b
nvd
CVE-2023-20041P4MEDIUMCVSS 6.1v6.4.0.16v6.6.7.1+8 more2023-11-01
CVE-2023-20041 [MEDIUM] CWE-79 CVE-2023-20041: Multiple vulnerabilities in the web-based management interface of Cisco Firepower Management Center
Multiple vulnerabilities in the web-based management interface of Cisco Firepower Management Center (FMC) Software could allow an unauthenticated, remote attacker to conduct a stored cross-site scripting (XSS) attack against a user of the interface of an affected device. These vulnerabilities are due to insufficient validation of user-supplied input b
nvd
CVE-2024-20372P4MEDIUMCVSS 6.1v6.2.3v6.2.3.1+75 more2024-10-23
CVE-2024-20372 [MEDIUM] CWE-79 CVE-2024-20372: A vulnerability in the web-based management interface of Cisco Firepower Management Center (FMC) Sof
A vulnerability in the web-based management interface of Cisco Firepower Management Center (FMC) Software could allow an unauthenticated, remote attacker to conduct a stored cross-site scripting (XSS) attack against a user of the interface of an affected device. This vulnerability is due to insufficient validation of user-supplied input by the web-ba
nvd
CVE-2024-20386P4MEDIUMCVSS 6.1v6.2.3v6.2.3.1+75 more2024-10-23
CVE-2024-20386 [MEDIUM] CWE-79 CVE-2024-20386: A vulnerability in the web-based management interface of Cisco Firepower Management Center (FMC) Sof
A vulnerability in the web-based management interface of Cisco Firepower Management Center (FMC) Software could allow an unauthenticated, remote attacker to conduct a stored cross-site scripting (XSS) attack against a user of the interface of an affected device. This vulnerability is due to insufficient validation of user-supplied input by the web-ba
nvd
CVE-2024-20410P4MEDIUMCVSS 6.1v6.2.3v6.2.3.1+75 more2024-10-23
CVE-2024-20410 [MEDIUM] CWE-79 CVE-2024-20410: A vulnerability in the web-based management interface of Cisco Firepower Management Center (FMC) Sof
A vulnerability in the web-based management interface of Cisco Firepower Management Center (FMC) Software could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface of an affected device. This vulnerability is due to insufficient validation of user-supplied input by the web-based man
nvd
CVE-2024-20415P4MEDIUMCVSS 6.1v6.2.3v6.2.3.1+75 more2024-10-23
CVE-2024-20415 [MEDIUM] CWE-79 CVE-2024-20415: A vulnerability in the web-based management interface of Cisco Firepower Management Center (FMC) Sof
A vulnerability in the web-based management interface of Cisco Firepower Management Center (FMC) Software could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface of an affected device. This vulnerability is due to insufficient validation of user-supplied input by the web-based man
nvd
CVE-2024-20409P4MEDIUMCVSS 6.1v6.2.3v6.2.3.1+75 more2024-10-23
CVE-2024-20409 [MEDIUM] CWE-79 CVE-2024-20409: A vulnerability in the web-based management interface of Cisco Firepower Management Center (FMC) Sof
A vulnerability in the web-based management interface of Cisco Firepower Management Center (FMC) Software could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface of an affected device. This vulnerability is due to insufficient validation of user-supplied input by the web-based man
nvd
CVE-2025-20235P4MEDIUMCVSS 6.1v6.2.3v6.2.3.1+92 more2025-08-14
CVE-2025-20235 [MEDIUM] CWE-79 CVE-2025-20235: A vulnerability in the web-based management interface of Cisco Secure Firewall Management Center (FM
A vulnerability in the web-based management interface of Cisco Secure Firewall Management Center (FMC) Software could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface.
This vulnerability is due to insufficient validation of user-supplied input by the web-based management interfa
nvd
CVE-2019-1930P4MEDIUMCVSS 6.1v6.2.3v6.3.0+2 more2019-07-06
CVE-2019-1930 [MEDIUM] CWE-79 CVE-2019-1930: Multiple vulnerabilities in the RSS dashboard in the web-based management interface of Cisco Firepow
Multiple vulnerabilities in the RSS dashboard in the web-based management interface of Cisco Firepower Management Center (FMC) could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web-based management interface of an affected device. The vulnerabilities are due to insufficient validation o
nvd
CVE-2019-1931P4MEDIUMCVSS 6.1v6.2.3v6.3.0+2 more2019-07-06
CVE-2019-1931 [MEDIUM] CWE-79 CVE-2019-1931: Multiple vulnerabilities in the RSS dashboard in the web-based management interface of Cisco Firepow
Multiple vulnerabilities in the RSS dashboard in the web-based management interface of Cisco Firepower Management Center (FMC) could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web-based management interface of an affected device. The vulnerabilities are due to insufficient validation o
nvd
CVE-2020-3557P4MEDIUMCVSS 5.3fixed in 6.6.12020-10-21
CVE-2020-3557 [MEDIUM] CWE-295 CVE-2020-3557: A vulnerability in the host input API daemon of Cisco Firepower Management Center (FMC) Software cou
A vulnerability in the host input API daemon of Cisco Firepower Management Center (FMC) Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. The vulnerability is due to improper certificate validation. An attacker could exploit this vulnerability by sending a crafted data stream t
nvd