VDB
CVE-2023-20048
CVE-2023-20048
PUBLISHED
Es besteht eine Schwachstelle in Cisco Firepower. Dieser Fehler besteht in der Management Center Software aufgrund einer unzureichenden Autorisierung von Konfigurationsbefehlen, die über die Web-Service-Schnittstelle gesendet werden. Durch die Authentifizierung an der FMC-Webdienstschnittstelle und das Senden einer manipulierten HTTP-Anfrage an ein betroffenes Gerät kann ein entfernter, authentifizierter Angreifer mit gültigen Anmeldeinformationen auf der FMC-Software diese Schwachstelle zur Ausführung von beliebigem Code ausnutzen.
EPSS 4.55% · 89.4th percentile
Risk Scores
EPSS Score
4.55%
89.4th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Cisco | Cisco Firepower Management Center |
Exploit Intelligence
- A CLI tool for detecting CVE-2023-20048 vulnerability in Cisco Firepower Management Center. (github-poc-repo)
- A CLI tool for detecting CVE-2023-20048 vulnerability in Cisco Firepower Management Center. (github-poc-repo)
- A CLI tool for detecting CVE-2023-20048 vulnerability in Cisco Firepower Management Center. (github-poc-repo)
- A CLI tool for detecting CVE-2023-20048 vulnerability in Cisco Firepower Management Center. (github-poc-repo)
- A CLI tool for detecting CVE-2023-20048 vulnerability in Cisco Firepower Management Center. (github-poc-repo)
- PoC and exploit scripts for CVE-2023-20048 - Remote Code Execution vulnerability affecting Cisco RV series routers. Includes a vulnerability checker (PoC) and a working exploit for gaining remote shell access. For educational and research purposes only. (github-poc-repo)
- PoC and exploit scripts for CVE-2023-20048 - Remote Code Execution vulnerability affecting Cisco RV series routers. Includes a vulnerability checker (PoC) and a working exploit for gaining remote shell access. For educational and research purposes only. (github-poc-repo)
- PoC and exploit scripts for CVE-2023-20048 - Remote Code Execution vulnerability affecting Cisco RV series routers. Includes a vulnerability checker (PoC) and a working exploit for gaining remote shell access. For educational and research purposes only. (github-poc-repo)
- PoC and exploit scripts for CVE-2023-20048 - Remote Code Execution vulnerability affecting Cisco RV series routers. Includes a vulnerability checker (PoC) and a working exploit for gaining remote shell access. For educational and research purposes only. (github-poc-repo)
- PoC and exploit scripts for CVE-2023-20048 - Remote Code Execution vulnerability affecting Cisco RV series routers. Includes a vulnerability checker (PoC) and a working exploit for gaining remote shell access. For educational and research purposes only. (github-poc-repo)
…and 13 more exploits
Timeline
- Nov 1, 2023 CVE Published
- Nov 2, 2023 EPSS Score
- Dec 3, 2023 EPSS Score
- Feb 2, 2024 EPSS Score
- Mar 4, 2024 EPSS Score
- Mar 12, 2024 PoC Published
- May 4, 2024 EPSS Score
- Jun 4, 2024 EPSS Score
- Jul 5, 2024 EPSS Score
- Sep 4, 2024 EPSS Score
- Oct 5, 2024 EPSS Score
- Dec 6, 2024 EPSS Score
References
- https://wid.cert-bund.de/.well-known/csaf/white/2023/wid-sec-w-2023-2811.json advisory
- https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2023-2811 advisory
- https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-fmc-xss-sK2gkfvJ advisory
- https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-fmc-logview-dos-AYJdeX55 advisory
- https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-fmc-file-download-7js4ug2J advisory
- https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-fmc-cmdinj-bTEgufOX advisory
- https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-fmc-cmd-inj-29MP49hN advisory