Command Injection Vulnerability in Cisco Firepower Management Center Software
CVE-2023-20220
8.8HIGH
Summary
Multiple vulnerabilities within the web-based management interface of Cisco Firepower Management Center (FMC) Software allow an authenticated, remote attacker to execute arbitrary commands on the operating system. These issues stem from insufficient validation of user-supplied input in particular configuration options. An attacker with valid device credentials can exploit these vulnerabilities through crafted input in the configuration GUI, potentially gaining unauthorized access to execute commands that may impair device functionality and availability.
Affected Version(s)
Cisco Firepower Management Center 6.2.3
Cisco Firepower Management Center 6.2.3.1
Cisco Firepower Management Center 6.2.3.2
References
CVSS V3.1
Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
- 👾
Exploit known to exist
Vulnerability published
Vulnerability Reserved