VDB

CISCO-SA-FMC-FILE-READ-5Q4MQRN

CISCO-SA-FMC-FILE-READ-5Q4MQRN PUBLISHED CVSS 6.5 MEDIUM

A vulnerability in the web-based management interface of Cisco Secure Firewall Management Center (FMC) Software, formerly Firepower Management Center Software, could allow an authenticated, remote attacker to read arbitrary files from the underlying operating system. This vulnerability exists because the web-based management interface does not properly validate user-supplied input. An attacker could exploit this vulnerability by sending a crafted HTTP request to an affected device. A successful exploit could allow the attacker to read arbitrary files on the underlying operating system of the affected device. The attacker would need valid user credentials to exploit this vulnerability. Cisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability. This advisory is part of the October 2024 release of the Cisco ASA, FMC, and FTD Software Security Advisory Bundled Publication. For a complete list of the advisories and links to them, see Cisco Event Response: October 2024 Semiannual Cisco ASA, FMC, and FTD Software Security Advisory Bundled Publication ["https://sec.cloudapps.cisco.com/security/center/viewErp.x?alertId=ERP-75300"].

Risk Scores

CVSS 3.1
6.5
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

Affected Products

VendorProductVersions
Cisco Firepower Management Center Appliances
7.3.1.2
7.3.1.1
7.3.1
7.3.0
CiscoCisco Firepower Management Center7.3.1.2, 7.4.0, 7.4.1

Timeline

  • Oct 23, 2024 CVE Published
Open in Interactive Console →
$ Console Community · 100/wk Open console ›