Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Sund0Y

#28515of 53,624
9Total CVSS
Vulnerabilities · 1
PT-2024-3779
9.0
2024-05-22
Cisco · Cisco Firepower Management Center · CVE-2024-20360
**Name of the Vulnerable Software and Affected Versions** Cisco Firepower Management Center (FMC) Software (affected versions not specified) **Description** The issue is related to the web-based management interface of Cisco Firepower Management Center (FMC) Software, which does not adequately validate user input, allowing an authenticated, remote attacker to conduct SQL injection attacks. An attacker could exploit this by sending crafted SQL queries to an affected system, potentially obtaining any data from the database, executing arbitrary commands on the underlying operating system, and elevating privileges to root. The attacker would need at least Read Only user credentials to exploit this. **Recommendations** At the moment, there is no information about a newer version that contains a fix for this vulnerability.