cbcvebase.

Cisco Secure Firewall Management Center vulnerabilities

178 known vulnerabilities affecting cisco/secure_firewall_management_center.

Total CVEs
178
CISA KEV
1
actively exploited
Public exploits
6
Exploited in wild
1
Severity breakdown
CRITICAL6HIGH56MEDIUM116

Vulnerabilities

Page 8 of 9
CVE-2017-6716P4MEDIUMCVSS 5.4v5.3.1.7v5.4.0+9 more2017-07-04
CVE-2017-6716 [MEDIUM] CWE-79 CVE-2017-6716: A vulnerability in the web framework code of Cisco Firepower Management Center could allow an authen A vulnerability in the web framework code of Cisco Firepower Management Center could allow an authenticated, remote attacker to conduct a stored cross-site scripting (XSS) attack against a user of the web interface of an affected system. Affected Products: Cisco Firepower Management Center Software Releases prior to 6.0.0.0. More Information: CSCuy8878
nvd
CVE-2017-6715P4MEDIUMCVSS 5.4v5.4.0v5.4.0.2+7 more2017-07-04
CVE-2017-6715 [MEDIUM] CWE-79 CVE-2017-6715: A vulnerability in the web framework of Cisco Firepower Management Center could allow an authenticat A vulnerability in the web framework of Cisco Firepower Management Center could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web interface. Affected Products: Cisco Firepower Management Center Releases 5.4.1.x and prior. More Information: CSCuy88951. Known Affected Releases: 5.4.1.6.
nvd
CVE-2020-3320P4MEDIUMCVSS 5.4≤ 6.6.12020-10-08
CVE-2020-3320 [MEDIUM] CWE-79 CVE-2020-3320: A vulnerability in the web-based management interface of Cisco Firepower Management Center could all A vulnerability in the web-based management interface of Cisco Firepower Management Center could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web-based management interface of an affected device. The vulnerability is due to insufficient validation of user-supplied input by the web-based ma
nvd
CVE-2016-1431P4MEDIUMCVSS 6.1v4.10.3v5.2.0+3 more2016-06-18
CVE-2016-1431 [MEDIUM] CWE-79 CVE-2016-1431: Cross-site scripting (XSS) vulnerability in Cisco Firepower Management Center 4.10.3, 5.2.0, 5.3.0, Cross-site scripting (XSS) vulnerability in Cisco Firepower Management Center 4.10.3, 5.2.0, 5.3.0, 5.3.1, and 5.4.0 allows remote attackers to inject arbitrary web script or HTML via a crafted URL, aka Bug ID CSCur25516.
nvd
CVE-2017-6717P4MEDIUMCVSS 5.4v5.4.0v5.4.0.2+20 more2017-07-04
CVE-2017-6717 [MEDIUM] CWE-79 CVE-2017-6717: A vulnerability in the web framework of Cisco Firepower Management Center could allow an authenticat A vulnerability in the web framework of Cisco Firepower Management Center could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web interface. More Information: CSCvc38801. Known Affected Releases: 6.0.1.3 6.2.1. Known Fixed Releases: 6.2.1.
nvd
CVE-2017-3847P4MEDIUMCVSS 5.4v6.2.12017-02-22
CVE-2017-3847 [MEDIUM] CWE-79 CVE-2017-3847: A vulnerability in the web framework of Cisco Firepower Management Center could allow an authenticat A vulnerability in the web framework of Cisco Firepower Management Center could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web interface. More Information: CSCvc72741. Known Affected Releases: 6.2.1.
nvd
CVE-2021-1477P4MEDIUMCVSS 4.3fixed in 6.4.0.12≥ 6.5.0, < 6.6.3+1 more2021-04-29
CVE-2021-1477 [MEDIUM] CWE-284 CVE-2021-1477: A vulnerability in an access control mechanism of Cisco Firepower Management Center (FMC) Software c A vulnerability in an access control mechanism of Cisco Firepower Management Center (FMC) Software could allow an authenticated, remote attacker to access services beyond the scope of their authorization. This vulnerability is due to insufficient enforcement of access control in the affected software. An attacker could exploit this vulnerability by di
nvd
CVE-2025-20302P4MEDIUMCVSS 4.3v6.2.3v6.2.3.1+90 more2025-08-14
CVE-2025-20302 [MEDIUM] CWE-862 CVE-2025-20302: A vulnerability in the web-based management interface of Cisco Secure FMC Software could allow an au A vulnerability in the web-based management interface of Cisco Secure FMC Software could allow an authenticated, low-privileged, remote attacker to retrieve a generated report from a different domain. This vulnerability is due to missing authorization checks. An attacker could exploit this vulnerability by directly accessing a generated report file
nvd
CVE-2021-34751P4MEDIUMCVSS 4.3fixed in 6.4.0.13≥ 6.5.0, < 6.6.5.1+2 more2024-11-15
CVE-2021-34751 [MEDIUM] CWE-317 CVE-2021-34751: A vulnerability in the administrative web-based GUI configuration manager of Cisco Firepower Managem A vulnerability in the administrative web-based GUI configuration manager of Cisco Firepower Management Center (FMC) Software could allow an authenticated, remote attacker to access sensitive configuration information. The attacker would require low privilege credentials on an affected device. This vulnerability exists because of improper encryption
nvd
CVE-2016-6365P4MEDIUMCVSS 6.1v4.10.3v5.2.0+4 more2016-08-23
CVE-2016-6365 [MEDIUM] CWE-79 CVE-2016-6365: Cross-site scripting (XSS) vulnerability in Cisco Firepower Management Center 4.10.3, 5.2.0, 5.3.0, Cross-site scripting (XSS) vulnerability in Cisco Firepower Management Center 4.10.3, 5.2.0, 5.3.0, 5.3.0.2, 5.3.1, and 5.4.0 allows remote attackers to inject arbitrary web script or HTML via unspecified parameters, aka Bug IDs CSCur25508 and CSCur25518.
nvd
CVE-2015-6411P4MEDIUMCVSS 5.0v5.4.1.3v6.0.0+1 more2015-12-15
CVE-2015-6411 [MEDIUM] CWE-200 CVE-2015-6411: Cisco FirePOWER Management Center 5.4.1.3, 6.0.0, and 6.0.1 provides verbose responses to requests f Cisco FirePOWER Management Center 5.4.1.3, 6.0.0, and 6.0.1 provides verbose responses to requests for help files, which allows remote attackers to obtain potentially sensitive version information by reading an unspecified field, aka Bug ID CSCux37061.
nvd
CVE-2022-20938P4MEDIUMCVSS 4.3v6.1.0v6.1.0.1+90 more2022-11-15
CVE-2022-20938 [MEDIUM] CWE-611 CVE-2022-20938: A vulnerability in the module import function of the administrative interface of Cisco Firepower Man A vulnerability in the module import function of the administrative interface of Cisco Firepower Management Center (FMC) Software could allow an authenticated, remote attacker to view sensitive information. This vulnerability is due to insufficient validation of the XML syntax when importing a module. An attacker could exploit this vulnerability by
nvd
CVE-2021-1455P4MEDIUMCVSS 4.8≤ 6.4.0.11≥ 6.5.0, < 6.6.3+1 more2021-04-29
CVE-2021-1455 [MEDIUM] CWE-79 CVE-2021-1455: Multiple vulnerabilities in the web-based management interface of Cisco Firepower Management Center Multiple vulnerabilities in the web-based management interface of Cisco Firepower Management Center (FMC) Software could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface. These vulnerabilities are due to insufficient validation of user-supplied input by the web-based management inte
nvd
CVE-2021-1456P4MEDIUMCVSS 4.8≤ 6.4.0.11≥ 6.5.0, < 6.6.3+1 more2021-04-29
CVE-2021-1456 [MEDIUM] CWE-79 CVE-2021-1456: Multiple vulnerabilities in the web-based management interface of Cisco Firepower Management Center Multiple vulnerabilities in the web-based management interface of Cisco Firepower Management Center (FMC) Software could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface. These vulnerabilities are due to insufficient validation of user-supplied input by the web-based management inte
nvd
CVE-2021-1458P4MEDIUMCVSS 4.8≤ 6.4.0.11≥ 6.5.0, < 6.6.3+1 more2021-04-29
CVE-2021-1458 [MEDIUM] CWE-79 CVE-2021-1458: Multiple vulnerabilities in the web-based management interface of Cisco Firepower Management Center Multiple vulnerabilities in the web-based management interface of Cisco Firepower Management Center (FMC) Software could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface. These vulnerabilities are due to insufficient validation of user-supplied input by the web-based management inte
nvd
CVE-2021-1457P4MEDIUMCVSS 4.8≤ 6.4.0.11≥ 6.5.0, < 6.6.3+1 more2021-04-29
CVE-2021-1457 [MEDIUM] CWE-79 CVE-2021-1457: Multiple vulnerabilities in the web-based management interface of Cisco Firepower Management Center Multiple vulnerabilities in the web-based management interface of Cisco Firepower Management Center (FMC) Software could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface. These vulnerabilities are due to insufficient validation of user-supplied input by the web-based management inte
nvd
CVE-2021-1239P4MEDIUMCVSS 4.8fixed in 6.7.02021-01-13
CVE-2021-1239 [MEDIUM] CWE-79 CVE-2021-1239: Multiple vulnerabilities in the web-based management interface of Cisco Firepower Management Center Multiple vulnerabilities in the web-based management interface of Cisco Firepower Management Center (FMC) could allow an authenticated, remote attacker to conduct a stored cross-site scripting (XSS) attack against a user of the interface of an affected system. The vulnerabilities exist because the web-based management interface does not properly validat
nvd
CVE-2021-1238P4MEDIUMCVSS 4.8fixed in 6.7.02021-01-13
CVE-2021-1238 [MEDIUM] CWE-79 CVE-2021-1238: Multiple vulnerabilities in the web-based management interface of Cisco Firepower Management Center Multiple vulnerabilities in the web-based management interface of Cisco Firepower Management Center (FMC) could allow an authenticated, remote attacker to conduct a stored cross-site scripting (XSS) attack against a user of the interface of an affected system. The vulnerabilities exist because the web-based management interface does not properly validat
nvd
CVE-2022-20932P4MEDIUMCVSS 4.8v6.1.0v6.1.0.1+90 more2022-11-15
CVE-2022-20932 [MEDIUM] CWE-79 CVE-2022-20932: Multiple vulnerabilities in the web-based management interface of Cisco Firepower Management Center Multiple vulnerabilities in the web-based management interface of Cisco Firepower Management Center (FMC) Software could allow an authenticated, remote attacker to conduct a stored cross-site scripting (XSS) attack against a user of the interface of an affected device. These vulnerabilities are due to insufficient validation of user-supplied input by
nvd
CVE-2022-20832P4MEDIUMCVSS 4.8v6.1.0v6.1.0.1+90 more2022-11-15
CVE-2022-20832 [MEDIUM] CWE-79 CVE-2022-20832: Multiple vulnerabilities in the web-based management interface of Cisco Firepower Management Center Multiple vulnerabilities in the web-based management interface of Cisco Firepower Management Center (FMC) Software could allow an authenticated, remote attacker to conduct a stored cross-site scripting (XSS) attack against a user of the interface of an affected device. These vulnerabilities are due to insufficient validation of user-supplied input by
nvd
Cisco Secure Firewall Management Center vulnerabilities | cvebase