Unauthorized Configuration Command Execution Vulnerability in Cisco Firepower Management Center Software
CVE-2023-20048
What is CVE-2023-20048?
A vulnerability in the web services interface of Cisco Firepower Management Center (FMC) Software allows an authenticated remote attacker to execute unauthorized configuration commands on a Firepower Threat Defense (FTD) device. Caused by insufficient authorization, this issue enables attackers with valid credentials to send specially crafted HTTP requests to the FMC, potentially compromising the configuration of the managed FTD device. Properly securing the FMC interface and implementing strict access controls are essential to mitigate risks associated with this vulnerability.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Cisco Firepower Management Center 6.2.3
Cisco Firepower Management Center 6.2.3.1
Cisco Firepower Management Center 6.2.3.2
References
CVSS V3.1
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved