PT-2024-3779 · Cisco · Cisco Firepower Management Center

Sund0Y

·

Published

2024-05-22

·

Updated

2024-11-26

·

CVE-2024-20360

CVSS v2.0

9.0

High

VectorAV:N/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Cisco Firepower Management Center (FMC) Software (affected versions not specified)
Description The issue is related to the web-based management interface of Cisco Firepower Management Center (FMC) Software, which does not adequately validate user input, allowing an authenticated, remote attacker to conduct SQL injection attacks. An attacker could exploit this by sending crafted SQL queries to an affected system, potentially obtaining any data from the database, executing arbitrary commands on the underlying operating system, and elevating privileges to root. The attacker would need at least Read Only user credentials to exploit this.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2024-04131
CVE-2024-20360

Affected Products

Cisco Firepower Management Center