Unauthorized Configuration Command Execution Vulnerability in Cisco Firepower Management Center Software
CVE-2023-20048

9.9CRITICAL

Key Information:

Vendor
Cisco
Vendor
CVE Published:
1 November 2023

Badges

πŸ‘Ύ Exploit Exists

Summary

A vulnerability in the web services interface of Cisco Firepower Management Center (FMC) Software allows an authenticated remote attacker to execute unauthorized configuration commands on a Firepower Threat Defense (FTD) device. Caused by insufficient authorization, this issue enables attackers with valid credentials to send specially crafted HTTP requests to the FMC, potentially compromising the configuration of the managed FTD device. Properly securing the FMC interface and implementing strict access controls are essential to mitigate risks associated with this vulnerability.

Affected Version(s)

Cisco Firepower Management Center 6.2.3

Cisco Firepower Management Center 6.2.3.1

Cisco Firepower Management Center 6.2.3.2

References

CVSS V3.1

Score:
9.9
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • 🟑

    Public PoC available

  • πŸ‘Ύ

    Exploit known to exist

  • Vulnerability published

  • Vulnerability Reserved

Collectors

NVD DatabaseMitre Database0 Proof of Concept(s)
.