VDB
CVE-2019-12691
CVE-2019-12691
PUBLISHED
CVSS 4.099999904632568 MEDIUM
A vulnerability in the web-based management interface of Cisco Firepower Management Center (FMC) Software could allow an authenticated, remote attacker to perform a directory traversal attack on an affected device. The vulnerability is due to insufficient input validation by the web-based management interface. An attacker could exploit this vulnerability by sending a crafted HTTP request to the web-based management interface. A successful exploit could allow the attacker to bypass Cisco FMC Software security restrictions and gain access to the underlying filesystem of the affected device.
EPSS 0.05% · 15.4th percentile
Risk Scores
CVSS 3.0
4.099999904632568
CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:C/C:N/I:L/A:N
EPSS Score
0.05%
15.4th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| cisco | secure_firewall_management_center | 0 |
| Cisco | Cisco Firepower Management Center | unspecified |
Exploit Intelligence
Timeline
- Oct 2, 2019 CVE Published
- Apr 14, 2021 EPSS Score
- Jun 23, 2021 EPSS Score
- Aug 24, 2021 EPSS Score
- Oct 26, 2021 EPSS Score
- Jan 6, 2022 EPSS Score
- Feb 4, 2022 EPSS Score
- Feb 28, 2022 EPSS Score
- Apr 1, 2022 EPSS Score
- May 1, 2022 EPSS Score
- Jul 3, 2022 EPSS Score
- Sep 4, 2022 EPSS Score