Cisco Secure Firewall Management Center Software Vulnerability Allows Arbitrary Code Execution

CVE-2024-20374
6.5MEDIUM

Key Information

Vendor
Cisco
Status
Cisco Firepower Management Center
Vendor
CVE Published:
23 October 2024

Badges

👾 Exploit Exists

Summary

A vulnerability in the web-based management interface of Cisco Secure Firewall Management Center (FMC) Software, formerly Firepower Management Center Software, could allow an authenticated, remote attacker with Administrator-level privileges to execute arbitrary commands on the underlying operating system. This vulnerability is due to insufficient input validation of certain HTTP request parameters that are sent to the web-based management interface. An attacker could exploit this vulnerability by authenticating to the Cisco FMC web-based management interface and sending a crafted HTTP request to an affected device. A successful exploit could allow the attacker to execute commands as the root user on the affected device. To exploit this vulnerability, an attacker would need Administrator-level credentials.

Affected Version(s)

Cisco Firepower Management Center = 6.7.0

Cisco Firepower Management Center = 6.7.0.1

Cisco Firepower Management Center = 6.7.0.2

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
High
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • 👾

    Exploit exists.

  • Risk change from: null to: 6.5 - (MEDIUM)

  • Vulnerability published.

Collectors

NVD DatabaseMitre Database
.