Command Injection Vulnerability in Cisco Firepower Management Center Software
CVE-2023-20220

8.8HIGH

Key Information:

Vendor
Cisco
Vendor
CVE Published:
1 November 2023

Badges

👾 Exploit Exists

Summary

Multiple vulnerabilities within the web-based management interface of Cisco Firepower Management Center (FMC) Software allow an authenticated, remote attacker to execute arbitrary commands on the operating system. These issues stem from insufficient validation of user-supplied input in particular configuration options. An attacker with valid device credentials can exploit these vulnerabilities through crafted input in the configuration GUI, potentially gaining unauthorized access to execute commands that may impair device functionality and availability.

Affected Version(s)

Cisco Firepower Management Center 6.2.3

Cisco Firepower Management Center 6.2.3.1

Cisco Firepower Management Center 6.2.3.2

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • 👾

    Exploit known to exist

  • Vulnerability published

  • Vulnerability Reserved

.