PT-2020-2512 · Cisco · Cisco Firepower Management Center

Published

2020-05-06

·

Updated

2024-11-26

·

CVE-2020-3302

CVSS v2.0

8.5

High

VectorAV:N/AC:L/Au:S/C:N/I:C/A:C
Name of the Vulnerable Software and Affected Versions Cisco Firepower Management Center (affected versions not specified)
Description The issue is due to insufficient input validation in the web UI of the software, allowing an authenticated, remote attacker to overwrite files on the file system of an affected device by uploading a specially crafted file. This could be done through the web UI on an affected device.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

RCE

Weakness Enumeration

Related Identifiers

BDU:2020-02523
CVE-2020-3302

Affected Products

Cisco Firepower Management Center