Access Control Bypass in Cisco Firepower Management Center Software
CVE-2024-20361

5.8MEDIUM

Key Information:

Badges

👾 Exploit Exists

Summary

This vulnerability occurs in the Object Groups for Access Control Lists (ACLs) feature of Cisco Firepower Management Center (FMC) Software. It allows an unauthenticated, remote attacker to exploit a misconfiguration during the deployment of Object Groups for ACLs from Cisco FMC to managed Cisco Firepower Threat Defense (FTD) devices. In environments running high-availability, after the affected FTD device experiences a reboot following the deployment of Object Groups, an attacker can send crafted traffic. A successful exploit enables the attacker to bypass the configured access controls, potentially allowing unauthorized access to devices intended to be protected by the vulnerable FTD device.

Affected Version(s)

Cisco Firepower Management Center 7.1.0

Cisco Firepower Management Center 7.1.0.1

Cisco Firepower Management Center 7.1.0.2

References

CVSS V3.1

Score:
5.8
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • 👾

    Exploit known to exist

  • Vulnerability published

.