Cross-Site Request Forgery Vulnerability in Cisco Firepower Management Center
CVE-2018-0365
8.8HIGH
Key Information:
- Vendor
- Cisco
- Vendor
- CVE Published:
- 21 June 2018
Summary
A vulnerability exists in the web-based management interface of Cisco Firepower Management Center that may allow an unauthenticated remote attacker to leverage cross-site request forgery (CSRF) techniques. The issue arises from inadequate CSRF protections which could enable an attacker to trick a legitimate user into clicking a malicious link. This action could lead to the execution of unauthorized commands on the affected device using the permissions of the unsuspecting user. Addressing this vulnerability is crucial to safeguarding your Cisco infrastructure from potential exploitation.
Affected Version(s)
Cisco Firepower Management Center unknown Cisco Firepower Management Center unknown
References
CVSS V3.1
Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved