PT-2021-2824 · Cisco · Cisco Firepower Device Manager (Fdm)+1

Published

2021-04-28

·

Updated

2021-05-09

·

CVE-2021-1489

CVSS v2.0

6.8

Medium

VectorAV:N/AC:L/Au:S/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions: Cisco Firepower Device Manager (FDM) Software (affected versions not specified) Cisco Firepower Management Center (FMC) (affected versions not specified)
Description: A vulnerability in filesystem usage management could allow an authenticated, remote attacker to exhaust filesystem resources, resulting in a denial of service (DoS) condition on an affected device. This is due to the insufficient management of available filesystem resources. An attacker could exploit this by uploading files to the device and exhausting available filesystem resources. A successful exploit could allow the attacker to cause database errors and make the device unresponsive to web-based management. Manual intervention is required to free filesystem resources and return the device to an operational state.
Recommendations: For Cisco Firepower Device Manager (FDM) Software, manually free filesystem resources to return the device to an operational state after an attack. For Cisco Firepower Management Center (FMC), restrict access to prevent remote attackers from uploading files and exhausting filesystem resources. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Resource Exhaustion

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2021-02370
CVE-2021-1489

Affected Products

Cisco Firepower Device Manager (Fdm)
Cisco Firepower Management Center