Cisco Secure Firewall Management Center (FMC) Software Vulnerability - Elevated Privileges Possible
CVE-2024-20482
6.5MEDIUM
What is CVE-2024-20482?
A privilege escalation vulnerability exists in the web-based management interface of Cisco Secure Firewall Management Center Software, previously known as Firepower Management Center Software. An attacker with a valid account and a custom read-only role may exploit this flaw due to inadequate validation of role permissions. By executing a write operation in the compromised part of the management interface, the attacker could gain the ability to alter critical aspects of the device's configuration, posing a significant security risk. Mitigation strategies should be implemented to safeguard against potential exploits.
Affected Version(s)
Cisco Firepower Management Center 7.2.0
Cisco Firepower Management Center 7.2.1
Cisco Firepower Management Center 7.2.2