VDB
CVE-2022-20938
CVE-2022-20938
PUBLISHED
CVSS 4.300000190734863 MEDIUM
A vulnerability in the module import function of the administrative interface of Cisco Firepower Management Center (FMC) Software could allow an authenticated, remote attacker to view sensitive information. This vulnerability is due to insufficient validation of the XML syntax when importing a module. An attacker could exploit this vulnerability by supplying a specially crafted XML file to the function. A successful exploit could allow the attacker to read sensitive data that would normally not be revealed.
EPSS 0.56% · 44.8th percentile
Risk Scores
CVSS 3.1
4.300000190734863
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
EPSS Score
0.56%
44.8th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Cisco | Cisco Firepower Management Center | 6.2.3, 6.2.3.1, 6.2.3.3 |
| cisco | secure_firewall_management_center | 6.1.0.4, 6.1.0, 6.1.0.1 |
Timeline
- Nov 10, 2022 CVE Published
- Nov 16, 2022 EPSS Score
- Dec 29, 2022 EPSS Score
- Feb 11, 2023 EPSS Score
- Mar 7, 2023 EPSS Score
- Mar 26, 2023 EPSS Score
- May 9, 2023 EPSS Score
- Jun 21, 2023 EPSS Score
- Aug 4, 2023 EPSS Score
- Sep 16, 2023 EPSS Score
- Oct 30, 2023 EPSS Score
- Dec 12, 2023 EPSS Score