Cisco Secure Firewall Management Center vulnerabilities
178 known vulnerabilities affecting cisco/secure_firewall_management_center.
Total CVEs
178
CISA KEV
1
actively exploited
Public exploits
6
Exploited in wild
1
Severity breakdown
CRITICAL6HIGH56MEDIUM116
Vulnerabilities
Page 7 of 9
CVE-2025-20218P4MEDIUMCVSS 4.9v6.2.3v6.2.3.1+85 more2025-08-14
CVE-2025-20218 [MEDIUM] CWE-643 CVE-2025-20218: A vulnerability in the web-based management interface of Cisco Secure Firewall Management Center (FM
A vulnerability in the web-based management interface of Cisco Secure Firewall Management Center (FMC) Software could allow an authenticated, remote attacker to retrieve sensitive information from an affected device.
This vulnerability is due to insufficient input validation. An attacker could exploit this vulnerability by sending a crafted request
nvd
CVE-2019-1671P4MEDIUMCVSS 6.1v6.0.0v6.1.0+5 more2019-02-07
CVE-2019-1671 [MEDIUM] CWE-79 CVE-2019-1671: A vulnerability in the web-based management interface of Cisco Firepower Management Center (FMC) cou
A vulnerability in the web-based management interface of Cisco Firepower Management Center (FMC) could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web-based management interface of an affected system. The vulnerability is due to insufficient validation of user-supplied input by the web-
nvd
CVE-2020-3553P4MEDIUMCVSS 6.1fixed in 6.6.12020-10-21
CVE-2020-3553 [MEDIUM] CWE-79 CVE-2020-3553: Multiple vulnerabilities in the web-based management interface of Cisco Firepower Management Center
Multiple vulnerabilities in the web-based management interface of Cisco Firepower Management Center (FMC) Software could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface. These vulnerabilities are due to insufficient validation of user-supplied input by the web-based management inte
nvd
CVE-2020-3515P4MEDIUMCVSS 6.1fixed in 6.6.12020-10-21
CVE-2020-3515 [MEDIUM] CWE-79 CVE-2020-3515: Multiple vulnerabilities in the web-based management interface of Cisco Firepower Management Center
Multiple vulnerabilities in the web-based management interface of Cisco Firepower Management Center (FMC) Software could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface. These vulnerabilities are due to insufficient validation of user-supplied input by the web-based management inte
nvd
CVE-2022-20740P4MEDIUMCVSS 6.1fixed in 6.6.5.2≥ 6.7.0, < 7.0.2+1 more2022-05-03
CVE-2022-20740 [MEDIUM] CWE-80 CVE-2022-20740: A vulnerability in the web-based management interface of Cisco Firepower Management Center (FMC) Sof
A vulnerability in the web-based management interface of Cisco Firepower Management Center (FMC) Software could allow an unauthenticated, remote attacker to conduct a cross-site scripting attack. This vulnerability is due to improper validation of user-supplied input to the web-based management interface. An attacker could exploit this vulnerability
nvd
CVE-2021-1126P4MEDIUMCVSS 5.5fixed in 6.7.02021-01-13
CVE-2021-1126 [MEDIUM] CWE-256 CVE-2021-1126: A vulnerability in the storage of proxy server credentials of Cisco Firepower Management Center (FMC
A vulnerability in the storage of proxy server credentials of Cisco Firepower Management Center (FMC) could allow an authenticated, local attacker to view credentials for a configured proxy server. The vulnerability is due to clear-text storage and weak permissions of related configuration files. An attacker could exploit this vulnerability by accessi
nvd
CVE-2024-20298P4MEDIUMCVSS 5.4v7.3.0v7.3.1+5 more2024-10-23
CVE-2024-20298 [MEDIUM] CWE-79 CVE-2024-20298: A vulnerability in the web-based management interface of Cisco Firepower Management Center (FMC) Sof
A vulnerability in the web-based management interface of Cisco Firepower Management Center (FMC) Software could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface of an affected device. This vulnerability is due to insufficient validation of user-supplied input by the web-based manag
nvd
CVE-2024-20264P4MEDIUMCVSS 5.4v7.1.0v7.1.0.1+13 more2024-10-23
CVE-2024-20264 [MEDIUM] CWE-79 CVE-2024-20264: A vulnerability in the web-based management interface of Cisco Firepower Management Center (FMC) Sof
A vulnerability in the web-based management interface of Cisco Firepower Management Center (FMC) Software could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface of an affected device. This vulnerability is due to insufficient validation of user-supplied input by the web-based manag
nvd
CVE-2024-20269P4MEDIUMCVSS 5.4v6.2.3v6.2.3.1+81 more2024-10-23
CVE-2024-20269 [MEDIUM] CWE-79 CVE-2024-20269: A vulnerability in the web-based management interface of Cisco Firepower Management Center (FMC) Sof
A vulnerability in the web-based management interface of Cisco Firepower Management Center (FMC) Software could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface of an affected device. This vulnerability is due to insufficient validation of user-supplied input by the web-based manag
nvd
CVE-2024-20300P4MEDIUMCVSS 5.4v6.2.3v6.2.3.1+83 more2024-10-23
CVE-2024-20300 [MEDIUM] CWE-79 CVE-2024-20300: A vulnerability in the web-based management interface of Cisco Firepower Management Center (FMC) Sof
A vulnerability in the web-based management interface of Cisco Firepower Management Center (FMC) Software could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface of an affected device. This vulnerability is due to insufficient validation of user-supplied input by the web-based manag
nvd
CVE-2024-20364P4MEDIUMCVSS 5.4v6.7.0v6.7.0.1+40 more2024-10-23
CVE-2024-20364 [MEDIUM] CWE-79 CVE-2024-20364: A vulnerability in the web-based management interface of Cisco Firepower Management Center (FMC) Sof
A vulnerability in the web-based management interface of Cisco Firepower Management Center (FMC) Software could allow an authenticated, remote attacker to conduct a stored cross-site scripting (XSS) attack against a user of the interface of an affected device. This vulnerability is due to insufficient validation of user-supplied input by the web-base
nvd
CVE-2024-20387P4MEDIUMCVSS 5.4v6.2.3.17v6.2.3.18+22 more2024-10-23
CVE-2024-20387 [MEDIUM] CWE-79 CVE-2024-20387: A vulnerability in the web-based management interface of Cisco FMC Software could allow an authentic
A vulnerability in the web-based management interface of Cisco FMC Software could allow an authenticated, remote attacker to store malicious content for use in XSS attacks. This vulnerability is due to improper input sanitization in the web-based management interface of Cisco FMC Software. An attacker could exploit this vulnerability by persuading a
nvd
CVE-2024-20403P4MEDIUMCVSS 5.4v6.2.3v6.2.3.1+75 more2024-10-23
CVE-2024-20403 [MEDIUM] CWE-79 CVE-2024-20403: A vulnerability in the web-based management interface of Cisco Firepower Management Center (FMC) Sof
A vulnerability in the web-based management interface of Cisco Firepower Management Center (FMC) Software could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface of an affected device. This vulnerability is due to insufficient validation of user-supplied input by the web-based manag
nvd
CVE-2020-3308P4MEDIUMCVSS 4.9v6.2.2v6.2.32020-05-06
CVE-2020-3308 [MEDIUM] CWE-347 CVE-2020-3308: A vulnerability in the Image Signature Verification feature of Cisco Firepower Threat Defense (FTD)
A vulnerability in the Image Signature Verification feature of Cisco Firepower Threat Defense (FTD) Software could allow an authenticated, remote attacker with administrator-level credentials to install a malicious software patch on an affected device. The vulnerability is due to improper verification of digital signatures for patch images. An attacker
nvd
CVE-2020-3313P4MEDIUMCVSS 6.1fixed in 6.2.2.32020-05-06
CVE-2020-3313 [MEDIUM] CWE-79 CVE-2020-3313: A vulnerability in the web UI of Cisco Firepower Management Center (FMC) Software could allow an una
A vulnerability in the web UI of Cisco Firepower Management Center (FMC) Software could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web-based management interface of the FMC Software. The vulnerability is due to insufficient validation of user-supplied input by the web-based management
nvd
CVE-2022-20628P4MEDIUMCVSS 5.4fixed in 6.4.0.15≥ 6.5.0, < 6.6.5.2+1 more2022-05-03
CVE-2022-20628 [MEDIUM] CWE-79 CVE-2022-20628: Multiple vulnerabilities in the web-based management interface of Cisco Firepower Management Center
Multiple vulnerabilities in the web-based management interface of Cisco Firepower Management Center (FMC) Software could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface. These vulnerabilities are due to insufficient validation of user-supplied input by the web-based management inte
nvd
CVE-2022-20629P4MEDIUMCVSS 5.4fixed in 6.4.0.15≥ 6.5.0, < 6.6.5.2+1 more2022-05-03
CVE-2022-20629 [MEDIUM] CWE-79 CVE-2022-20629: Multiple vulnerabilities in the web-based management interface of Cisco Firepower Management Center
Multiple vulnerabilities in the web-based management interface of Cisco Firepower Management Center (FMC) Software could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface. These vulnerabilities are due to insufficient validation of user-supplied input by the web-based management inte
nvd
CVE-2022-20627P4MEDIUMCVSS 5.4fixed in 6.4.0.15≥ 6.5.0, < 6.6.5.2+1 more2022-05-03
CVE-2022-20627 [MEDIUM] CWE-79 CVE-2022-20627: Multiple vulnerabilities in the web-based management interface of Cisco Firepower Management Center
Multiple vulnerabilities in the web-based management interface of Cisco Firepower Management Center (FMC) Software could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface. These vulnerabilities are due to insufficient validation of user-supplied input by the web-based management inte
nvd
CVE-2024-20377P4MEDIUMCVSS 5.4v7.0.0v7.0.0.1+37 more2024-10-23
CVE-2024-20377 [MEDIUM] CWE-79 CVE-2024-20377: A vulnerability in the web-based management interface of Cisco Firepower Management Center (FMC) cou
A vulnerability in the web-based management interface of Cisco Firepower Management Center (FMC) could allow an authenticated, remote attacker to conduct a stored cross-site scripting (XSS) attack against a user of the interface.
This vulnerability is due to the web-based management interface not properly validating user-supplied input. An attacker c
nvd
CVE-2016-1342P4MEDIUMCVSS 5.3v5.3.0.3v5.3.1.3+15 more2016-02-26
CVE-2016-1342 [MEDIUM] CWE-200 CVE-2016-1342: The device login page in Cisco FirePOWER Management Center 5.3 through 6.0.0.1 allows remote attacke
The device login page in Cisco FirePOWER Management Center 5.3 through 6.0.0.1 allows remote attackers to obtain potentially sensitive software-version information by reading help files, aka Bug ID CSCuy36654.
nvd