PT-2024-9445 · Cisco · Cisco Secure Firewall Management Center

Published

2024-10-23

·

Updated

2026-03-04

·

CVE-2024-20340

CVSS v2.0

6.8

Medium

VectorAV:N/AC:L/Au:S/C:C/I:N/A:N
Name of the Vulnerable Software and Affected Versions: Cisco Secure Firewall Management Center (formerly Cisco Firepower Management Center) versions not specified
Description: The issue is related to insufficient validation of user-supplied input, allowing an authenticated, remote attacker to perform an SQL injection attack against an affected device. To exploit this, an attacker must have a valid account on the device with a specific role, such as Security Approver, Intrusion Admin, Access Admin, or Network Admin. The attacker could exploit this by sending a crafted HTTP request to the web-based management interface of an affected device. A successful exploit could allow the attacker to read the contents of databases on the affected device and obtain limited read access to the underlying operating system.
Recommendations: At the moment, there is no information about a newer version that contains a fix for this vulnerability.

SQL injection

Weakness Enumeration

Related Identifiers

BDU:2024-11140
CVE-2024-20340

Affected Products

Cisco Secure Firewall Management Center