PT-2021-2824 · Cisco · Cisco Firepower Device Manager (Fdm)+1
Published
2021-04-28
·
Updated
2021-05-09
·
CVE-2021-1489
CVSS v2.0
6.8
Medium
| Vector | AV:N/AC:L/Au:S/C:N/I:N/A:C |
Name of the Vulnerable Software and Affected Versions:
Cisco Firepower Device Manager (FDM) Software (affected versions not specified)
Cisco Firepower Management Center (FMC) (affected versions not specified)
Description:
A vulnerability in filesystem usage management could allow an authenticated, remote attacker to exhaust filesystem resources, resulting in a denial of service (DoS) condition on an affected device. This is due to the insufficient management of available filesystem resources. An attacker could exploit this by uploading files to the device and exhausting available filesystem resources. A successful exploit could allow the attacker to cause database errors and make the device unresponsive to web-based management. Manual intervention is required to free filesystem resources and return the device to an operational state.
Recommendations:
For Cisco Firepower Device Manager (FDM) Software, manually free filesystem resources to return the device to an operational state after an attack.
For Cisco Firepower Management Center (FMC), restrict access to prevent remote attackers from uploading files and exhausting filesystem resources.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Resource Exhaustion
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Cisco Firepower Device Manager (Fdm)
Cisco Firepower Management Center