Unauthorized Configuration Command Execution Vulnerability in Cisco Firepower Management Center Software
CVE-2023-20048
Summary
A vulnerability in the web services interface of Cisco Firepower Management Center (FMC) Software allows an authenticated remote attacker to execute unauthorized configuration commands on a Firepower Threat Defense (FTD) device. Caused by insufficient authorization, this issue enables attackers with valid credentials to send specially crafted HTTP requests to the FMC, potentially compromising the configuration of the managed FTD device. Properly securing the FMC interface and implementing strict access controls are essential to mitigate risks associated with this vulnerability.
Affected Version(s)
Cisco Firepower Management Center 6.2.3
Cisco Firepower Management Center 6.2.3.1
Cisco Firepower Management Center 6.2.3.2
References
CVSS V3.1
Timeline
- π‘
Public PoC available
- πΎ
Exploit known to exist
Vulnerability published
Vulnerability Reserved