Cisco Firepower Management Center Software Vulnerability: Sensitive Configuration Information at Risk
CVE-2021-34750
4.3MEDIUM
Key Information:
- Vendor
- Cisco
- Vendor
- CVE Published:
- 15 November 2024
Summary
A vulnerability exists in the web-based GUI configuration manager of Cisco Firepower Management Center Software, which may permit an authenticated, remote attacker with low privilege credentials to access sensitive configuration details. This issue arises from inadequate encryption of sensitive data stored within the GUI. Exploiting this vulnerability involves logging into the Firepower Management Center GUI and accessing specific sensitive configurations, which could allow exposure of crucial configuration parameters in plain text. Cisco has addressed this issue through software updates, and no workarounds are available.
Affected Version(s)
Cisco Firepower Management Center
References
CVSS V3.1
Score:
4.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved