Access Control Bypass in Cisco Firepower Management Center Software
CVE-2024-20361
Summary
This vulnerability occurs in the Object Groups for Access Control Lists (ACLs) feature of Cisco Firepower Management Center (FMC) Software. It allows an unauthenticated, remote attacker to exploit a misconfiguration during the deployment of Object Groups for ACLs from Cisco FMC to managed Cisco Firepower Threat Defense (FTD) devices. In environments running high-availability, after the affected FTD device experiences a reboot following the deployment of Object Groups, an attacker can send crafted traffic. A successful exploit enables the attacker to bypass the configured access controls, potentially allowing unauthorized access to devices intended to be protected by the vulnerable FTD device.
Affected Version(s)
Cisco Firepower Management Center 7.1.0
Cisco Firepower Management Center 7.1.0.1
Cisco Firepower Management Center 7.1.0.2
References
CVSS V3.1
Timeline
- 👾
Exploit known to exist
Vulnerability published