Cisco Secure Firewall Management Center vulnerabilities
178 known vulnerabilities affecting cisco/secure_firewall_management_center.
Total CVEs
178
CISA KEV
1
actively exploited
Public exploits
6
Exploited in wild
0
Severity breakdown
CRITICAL6HIGH56MEDIUM116
Vulnerabilities
Page 9 of 9
CVE-2016-6368HIGHCVSS 8.6v6.0.0v6.0.0.0+2 more2017-04-20
CVE-2016-6368 [HIGH] CWE-399 CVE-2016-6368: A vulnerability in the detection engine parsing of Pragmatic General Multicast (PGM) protocol packet
A vulnerability in the detection engine parsing of Pragmatic General Multicast (PGM) protocol packets for Cisco Firepower System Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition due to the Snort process unexpectedly restarting. The vulnerability is due to improper input validation of the fields in the
nvd
CVE-2017-3885MEDIUMCVSS 5.9v6.0.0v6.1.0+2 more2017-04-07
CVE-2017-3885 [MEDIUM] CWE-400 CVE-2017-3885: A vulnerability in the detection engine reassembly of Secure Sockets Layer (SSL) packets for Cisco F
A vulnerability in the detection engine reassembly of Secure Sockets Layer (SSL) packets for Cisco Firepower System Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition because the Snort process consumes a high level of CPU resources. Affected Products: This vulnerability affects Cisco Firepower System
nvd
CVE-2017-3847MEDIUMCVSS 5.4v6.2.12017-02-22
CVE-2017-3847 [MEDIUM] CWE-79 CVE-2017-3847: A vulnerability in the web framework of Cisco Firepower Management Center could allow an authenticat
A vulnerability in the web framework of Cisco Firepower Management Center could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web interface. More Information: CSCvc72741. Known Affected Releases: 6.2.1.
nvd
CVE-2017-3814MEDIUMCVSS 5.8v5.3.0v5.4.0+3 more2017-02-03
CVE-2017-3814 [MEDIUM] CWE-20 CVE-2017-3814: A vulnerability in Cisco Firepower System Software could allow an unauthenticated, remote attacker t
A vulnerability in Cisco Firepower System Software could allow an unauthenticated, remote attacker to maliciously bypass the appliance's ability to block certain web content, aka a URL Bypass. More Information: CSCvb93980. Known Affected Releases: 5.3.0 5.4.0 6.0.0 6.0.1 6.1.0.
nvd
CVE-2017-3809MEDIUMCVSS 5.8v6.1.0v6.2.02017-02-03
CVE-2017-3809 [MEDIUM] CWE-20 CVE-2017-3809: A vulnerability in the Policy deployment module of the Cisco Firepower Management Center (FMC) could
A vulnerability in the Policy deployment module of the Cisco Firepower Management Center (FMC) could allow an unauthenticated, remote attacker to prevent deployment of a complete and accurate rule base. More Information: CSCvb95281. Known Affected Releases: 6.1.0 6.2.0. Known Fixed Releases: 6.1.0.1 6.2.0.
nvd
CVE-2016-9193HIGHCVSS 7.5v6.0.0v6.0.0.0+4 more2016-12-14
CVE-2016-9193 [HIGH] CWE-20 CVE-2016-9193: A vulnerability in the malicious file detection and blocking features of Cisco Firepower Management
A vulnerability in the malicious file detection and blocking features of Cisco Firepower Management Center and Cisco FireSIGHT System Software could allow an unauthenticated, remote attacker to bypass malware detection mechanisms on an affected system. Affected Products: Cisco Firepower Management Center and FireSIGHT System Software are affected when the
nvd
CVE-2016-6439HIGHCVSS 7.5v5.3.0v5.3.0.2+22 more2016-10-27
CVE-2016-6439 [HIGH] CWE-399 CVE-2016-6439: A vulnerability in the detection engine reassembly of HTTP packets for Cisco Firepower System Softwa
A vulnerability in the detection engine reassembly of HTTP packets for Cisco Firepower System Software before 6.0.1 could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition due to the Snort process unexpectedly restarting. The vulnerability is due to improper handling of an HTTP packet stream. An attacker could exploi
nvd
CVE-2016-6433HIGHCVSS 8.8PoCv5.2.0v5.3.0+18 more2016-10-06
CVE-2016-6433 [HIGH] CWE-20 CVE-2016-6433: The Threat Management Console in Cisco Firepower Management Center 5.2.0 through 6.0.1 allows remote
The Threat Management Console in Cisco Firepower Management Center 5.2.0 through 6.0.1 allows remote authenticated users to execute arbitrary commands via crafted web-application parameters, aka Bug ID CSCva30872.
nvd
CVE-2016-6434HIGHCVSS 7.8PoCv6.0.12016-10-06
CVE-2016-6434 [HIGH] CWE-287 CVE-2016-6434: Cisco Firepower Management Center 6.0.1 has hardcoded database credentials, which allows local users
Cisco Firepower Management Center 6.0.1 has hardcoded database credentials, which allows local users to obtain sensitive information by leveraging CLI access, aka Bug ID CSCva30370.
nvd
CVE-2016-6435MEDIUMCVSS 6.5PoCv6.0.12016-10-06
CVE-2016-6435 [MEDIUM] CWE-200 CVE-2016-6435: The web console in Cisco Firepower Management Center 6.0.1 allows remote authenticated users to read
The web console in Cisco Firepower Management Center 6.0.1 allows remote authenticated users to read arbitrary files via crafted parameters, aka Bug ID CSCva30376.
nvd
CVE-2016-6419HIGHCVSS 7.5v4.10.3v5.2.0+3 more2016-10-05
CVE-2016-6419 [HIGH] CWE-89 CVE-2016-6419: SQL injection vulnerability in Cisco Firepower Management Center 4.10.3 through 5.4.0 allows remote
SQL injection vulnerability in Cisco Firepower Management Center 4.10.3 through 5.4.0 allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors, aka Bug ID CSCur25485.
nvd
CVE-2016-6365MEDIUMCVSS 6.1v4.10.3v5.2.0+4 more2016-08-23
CVE-2016-6365 [MEDIUM] CWE-79 CVE-2016-6365: Cross-site scripting (XSS) vulnerability in Cisco Firepower Management Center 4.10.3, 5.2.0, 5.3.0,
Cross-site scripting (XSS) vulnerability in Cisco Firepower Management Center 4.10.3, 5.2.0, 5.3.0, 5.3.0.2, 5.3.1, and 5.4.0 allows remote attackers to inject arbitrary web script or HTML via unspecified parameters, aka Bug IDs CSCur25508 and CSCur25518.
nvd
CVE-2016-1458HIGHCVSS 8.8v4.10.3v5.2.0+3 more2016-08-18
CVE-2016-1458 [HIGH] CWE-264 CVE-2016-1458: The web-based GUI in Cisco Firepower Management Center 4.x and 5.x before 5.3.0.3, 5.3.1.x before 5.
The web-based GUI in Cisco Firepower Management Center 4.x and 5.x before 5.3.0.3, 5.3.1.x before 5.3.1.2, and 5.4.x before 5.4.0.1 and Cisco Adaptive Security Appliance (ASA) Software on 5500-X devices with FirePOWER Services 4.x and 5.x before 5.3.0.3, 5.3.1.x before 5.3.1.2, and 5.4.x before 5.4.0.1 allows remote authenticated users to increase user-
nvd
CVE-2016-1457HIGHCVSS 8.8v4.10.3.9v5.2.0+3 more2016-08-18
CVE-2016-1457 [HIGH] CWE-264 CVE-2016-1457: The web-based GUI in Cisco Firepower Management Center 4.x and 5.x before 5.3.1.2 and 5.4.x before 5
The web-based GUI in Cisco Firepower Management Center 4.x and 5.x before 5.3.1.2 and 5.4.x before 5.4.0.1 and Cisco Adaptive Security Appliance (ASA) Software on 5500-X devices with FirePOWER Services 4.x and 5.x before 5.3.1.2 and 5.4.x before 5.4.0.1 allows remote authenticated users to execute arbitrary commands as root via crafted HTTP requests, ak
nvd
CVE-2016-1431MEDIUMCVSS 6.1v4.10.3v5.2.0+3 more2016-06-18
CVE-2016-1431 [MEDIUM] CWE-79 CVE-2016-1431: Cross-site scripting (XSS) vulnerability in Cisco Firepower Management Center 4.10.3, 5.2.0, 5.3.0,
Cross-site scripting (XSS) vulnerability in Cisco Firepower Management Center 4.10.3, 5.2.0, 5.3.0, 5.3.1, and 5.4.0 allows remote attackers to inject arbitrary web script or HTML via a crafted URL, aka Bug ID CSCur25516.
nvd
CVE-2016-1413MEDIUMCVSS 6.5v5.4.0v5.4.0.2+8 more2016-05-28
CVE-2016-1413 [MEDIUM] CWE-94 CVE-2016-1413: The web interface in Cisco Firepower Management Center 5.4.0 through 6.0.0.1 allows remote authentic
The web interface in Cisco Firepower Management Center 5.4.0 through 6.0.0.1 allows remote authenticated users to modify pages by placing crafted code in a parameter value, aka Bug ID CSCuy76517.
nvd
CVE-2016-1342MEDIUMCVSS 5.3v5.3.0.3v5.3.1.3+15 more2016-02-26
CVE-2016-1342 [MEDIUM] CWE-200 CVE-2016-1342: The device login page in Cisco FirePOWER Management Center 5.3 through 6.0.0.1 allows remote attacke
The device login page in Cisco FirePOWER Management Center 5.3 through 6.0.0.1 allows remote attackers to obtain potentially sensitive software-version information by reading help files, aka Bug ID CSCuy36654.
nvd
CVE-2015-6411MEDIUMCVSS 5.0v5.4.1.3v6.0.0+1 more2015-12-15
CVE-2015-6411 [MEDIUM] CWE-200 CVE-2015-6411: Cisco FirePOWER Management Center 5.4.1.3, 6.0.0, and 6.0.1 provides verbose responses to requests f
Cisco FirePOWER Management Center 5.4.1.3, 6.0.0, and 6.0.1 provides verbose responses to requests for help files, which allows remote attackers to obtain potentially sensitive version information by reading an unspecified field, aka Bug ID CSCux37061.
nvd
← Previous9 / 9