cbcvebase.

Cisco Secure Firewall Management Center vulnerabilities

178 known vulnerabilities affecting cisco/secure_firewall_management_center.

Total CVEs
178
CISA KEV
1
actively exploited
Public exploits
6
Exploited in wild
1
Severity breakdown
CRITICAL6HIGH56MEDIUM116

Vulnerabilities

Page 9 of 9
CVE-2022-20835P4MEDIUMCVSS 4.8v6.1.0v6.1.0.1+90 more2022-11-15
CVE-2022-20835 [MEDIUM] CWE-79 CVE-2022-20835: Multiple vulnerabilities in the web-based management interface of Cisco Firepower Management Center Multiple vulnerabilities in the web-based management interface of Cisco Firepower Management Center (FMC) Software could allow an authenticated, remote attacker to conduct a stored cross-site scripting (XSS) attack against a user of the interface of an affected device. These vulnerabilities are due to insufficient validation of user-supplied input by
nvd
CVE-2022-20843P4MEDIUMCVSS 4.8v6.1.0v6.1.0.1+90 more2022-11-15
CVE-2022-20843 [MEDIUM] CWE-79 CVE-2022-20843: Multiple vulnerabilities in the web-based management interface of Cisco Firepower Management Center Multiple vulnerabilities in the web-based management interface of Cisco Firepower Management Center (FMC) Software could allow an authenticated, remote attacker to conduct a stored cross-site scripting (XSS) attack against a user of the interface of an affected device. These vulnerabilities are due to insufficient validation of user-supplied input by
nvd
CVE-2022-20833P4MEDIUMCVSS 4.8v6.1.0v6.1.0.1+90 more2022-11-15
CVE-2022-20833 [MEDIUM] CWE-79 CVE-2022-20833: Multiple vulnerabilities in the web-based management interface of Cisco Firepower Management Center Multiple vulnerabilities in the web-based management interface of Cisco Firepower Management Center (FMC) Software could allow an authenticated, remote attacker to conduct a stored cross-site scripting (XSS) attack against a user of the interface of an affected device. These vulnerabilities are due to insufficient validation of user-supplied input by
nvd
CVE-2022-20840P4MEDIUMCVSS 4.8v6.1.0v6.1.0.1+90 more2022-11-15
CVE-2022-20840 [MEDIUM] CWE-79 CVE-2022-20840: Multiple vulnerabilities in the web-based management interface of Cisco Firepower Management Center Multiple vulnerabilities in the web-based management interface of Cisco Firepower Management Center (FMC) Software could allow an authenticated, remote attacker to conduct a stored cross-site scripting (XSS) attack against a user of the interface of an affected device. These vulnerabilities are due to insufficient validation of user-supplied input by
nvd
CVE-2022-20831P4MEDIUMCVSS 4.8v6.1.0v6.1.0.1+90 more2022-11-15
CVE-2022-20831 [MEDIUM] CWE-79 CVE-2022-20831: Multiple vulnerabilities in the web-based management interface of Cisco Firepower Management Center Multiple vulnerabilities in the web-based management interface of Cisco Firepower Management Center (FMC) Software could allow an authenticated, remote attacker to conduct a stored cross-site scripting (XSS) attack against a user of the interface of an affected device. These vulnerabilities are due to insufficient validation of user-supplied input by
nvd
CVE-2022-20839P4MEDIUMCVSS 4.8v6.1.0v6.1.0.1+90 more2022-11-15
CVE-2022-20839 [MEDIUM] CWE-79 CVE-2022-20839: Multiple vulnerabilities in the web-based management interface of Cisco Firepower Management Center Multiple vulnerabilities in the web-based management interface of Cisco Firepower Management Center (FMC) Software could allow an authenticated, remote attacker to conduct a stored cross-site scripting (XSS) attack against a user of the interface of an affected device. These vulnerabilities are due to insufficient validation of user-supplied input by
nvd
CVE-2022-20935P4MEDIUMCVSS 4.8v6.1.0v6.1.0.1+90 more2022-11-15
CVE-2022-20935 [MEDIUM] CWE-79 CVE-2022-20935: Multiple vulnerabilities in the web-based management interface of Cisco Firepower Management Center Multiple vulnerabilities in the web-based management interface of Cisco Firepower Management Center (FMC) Software could allow an authenticated, remote attacker to conduct a stored cross-site scripting (XSS) attack against a user of the interface of an affected device. These vulnerabilities are due to insufficient validation of user-supplied input by
nvd
CVE-2022-20905P4MEDIUMCVSS 4.8v6.1.0v6.1.0.1+90 more2022-11-15
CVE-2022-20905 [MEDIUM] CWE-79 CVE-2022-20905: Multiple vulnerabilities in the web-based management interface of Cisco Firepower Management Center Multiple vulnerabilities in the web-based management interface of Cisco Firepower Management Center (FMC) Software could allow an authenticated, remote attacker to conduct a stored cross-site scripting (XSS) attack against a user of the interface of an affected device. These vulnerabilities are due to insufficient validation of user-supplied input by
nvd
CVE-2022-20834P4MEDIUMCVSS 4.8v6.1.0v6.1.0.1+90 more2022-11-15
CVE-2022-20834 [MEDIUM] CWE-79 CVE-2022-20834: Multiple vulnerabilities in the web-based management interface of Cisco Firepower Management Center Multiple vulnerabilities in the web-based management interface of Cisco Firepower Management Center (FMC) Software could allow an authenticated, remote attacker to conduct a stored cross-site scripting (XSS) attack against a user of the interface of an affected device. These vulnerabilities are due to insufficient validation of user-supplied input by
nvd
CVE-2022-20836P4MEDIUMCVSS 4.8v6.1.0v6.1.0.1+90 more2022-11-15
CVE-2022-20836 [MEDIUM] CWE-79 CVE-2022-20836: Multiple vulnerabilities in the web-based management interface of Cisco Firepower Management Center Multiple vulnerabilities in the web-based management interface of Cisco Firepower Management Center (FMC) Software could allow an authenticated, remote attacker to conduct a stored cross-site scripting (XSS) attack against a user of the interface of an affected device. These vulnerabilities are due to insufficient validation of user-supplied input by
nvd
CVE-2022-20838P4MEDIUMCVSS 4.8v6.1.0v6.1.0.1+90 more2022-11-15
CVE-2022-20838 [MEDIUM] CWE-79 CVE-2022-20838: Multiple vulnerabilities in the web-based management interface of Cisco Firepower Management Center Multiple vulnerabilities in the web-based management interface of Cisco Firepower Management Center (FMC) Software could allow an authenticated, remote attacker to conduct a stored cross-site scripting (XSS) attack against a user of the interface of an affected device. These vulnerabilities are due to insufficient validation of user-supplied input by
nvd
CVE-2022-20936P4MEDIUMCVSS 4.8v6.1.0v6.1.0.1+90 more2022-11-15
CVE-2022-20936 [MEDIUM] CWE-79 CVE-2022-20936: Multiple vulnerabilities in the web-based management interface of Cisco Firepower Management Center Multiple vulnerabilities in the web-based management interface of Cisco Firepower Management Center (FMC) Software could allow an authenticated, remote attacker to conduct a stored cross-site scripting (XSS) attack against a user of the interface of an affected device. These vulnerabilities are due to insufficient validation of user-supplied input by
nvd
CVE-2022-20872P4MEDIUMCVSS 4.8v6.1.0v6.1.0.1+90 more2022-11-15
CVE-2022-20872 [MEDIUM] CWE-79 CVE-2022-20872: Multiple vulnerabilities in the web-based management interface of Cisco Firepower Management Center Multiple vulnerabilities in the web-based management interface of Cisco Firepower Management Center (FMC) Software could allow an authenticated, remote attacker to conduct a stored cross-site scripting (XSS) attack against a user of the interface of an affected device. These vulnerabilities are due to insufficient validation of user-supplied input by
nvd
CVE-2019-1802P4MEDIUMCVSS 4.8v6.2.3v6.3.0+1 more2019-04-18
CVE-2019-1802 [MEDIUM] CWE-79 CVE-2019-1802: A vulnerability in the web-based management interface of Cisco Firepower Management Center (FMC) cou A vulnerability in the web-based management interface of Cisco Firepower Management Center (FMC) could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web-based management interface of an affected system. The vulnerability is due to insufficient validation of user-supplied input in the web-ba
nvd
CVE-2019-15280P4MEDIUMCVSS 4.8v6.2.0v6.2.3+3 more2019-10-16
CVE-2019-15280 [MEDIUM] CWE-79 CVE-2019-15280: A vulnerability in the web-based management interface of Cisco Firepower Management Center (FMC) Sof A vulnerability in the web-based management interface of Cisco Firepower Management Center (FMC) Software could allow an authenticated, remote attacker to conduct a stored cross-site scripting (XSS) attack against a user of the web-based management interface. The vulnerability is due to insufficient validation of user-supplied input by the web-based
nvd
CVE-2021-1267P4MEDIUMCVSS 4.3fixed in 6.6.12021-01-13
CVE-2021-1267 [MEDIUM] CWE-776 CVE-2021-1267: A vulnerability in the dashboard widget of Cisco Firepower Management Center (FMC) Software could al A vulnerability in the dashboard widget of Cisco Firepower Management Center (FMC) Software could allow an authenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. The vulnerability is due to improper restrictions on XML entities. An attacker could exploit this vulnerability by crafting an XML-based widget on
nvd
CVE-2019-1949P4MEDIUMCVSS 4.8v6.1.0v6.2.1+4 more2019-08-08
CVE-2019-1949 [MEDIUM] CWE-79 CVE-2019-1949: A vulnerability in the web-based management interface of Cisco Firepower Management Center could all A vulnerability in the web-based management interface of Cisco Firepower Management Center could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web-based management interface of an affected system. The vulnerability is due to insufficient validation of user-supplied input by the web-based ma
nvd
CVE-2020-3301P4MEDIUMCVSS 4.4v2.0.3v2.1.0+11 more2020-05-06
CVE-2020-3301 [MEDIUM] CWE-798 CVE-2020-3301: Multiple vulnerabilities in Cisco Firepower Management Center (FMC) Software and Cisco Firepower Use Multiple vulnerabilities in Cisco Firepower Management Center (FMC) Software and Cisco Firepower User Agent Software could allow an attacker to access a sensitive part of an affected system with a high-privileged account. For more information about these vulnerabilities, see the Details section of this advisory.
nvd