Cisco Firepower Management Center Software Vulnerability: Sensitive Configuration Information at Risk
CVE-2021-34750

4.3MEDIUM

Key Information:

Vendor
Cisco
Vendor
CVE Published:
15 November 2024

Summary

A vulnerability exists in the web-based GUI configuration manager of Cisco Firepower Management Center Software, which may permit an authenticated, remote attacker with low privilege credentials to access sensitive configuration details. This issue arises from inadequate encryption of sensitive data stored within the GUI. Exploiting this vulnerability involves logging into the Firepower Management Center GUI and accessing specific sensitive configurations, which could allow exposure of crucial configuration parameters in plain text. Cisco has addressed this issue through software updates, and no workarounds are available.

Affected Version(s)

Cisco Firepower Management Center

References

CVSS V3.1

Score:
4.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.