VDB
GCVE-VVD-NCSC-2026-77
GCVE-VVD-NCSC-2026-77
Advisory PublishedCVSS 6.5/10
Multiple vulnerabilities in Cisco products, including an SQL injection flaw in Cisco Secure Firewall Management Center, allow authenticated users or remote attackers to perform actions such as SQL injection, denial of service, privilege escalation, remote code execution, and information disclosure.
Weaknesses (CWE)
CWE-89Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')CWE-78Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')CWE-330Use of Insufficiently Random ValuesCWE-20Improper Input ValidationCWE-284Improper Access ControlCWE-27Path Traversal: 'dir/../../filename'CWE-401Missing Release of Memory after Effective LifetimeCWE-279Incorrect Execution-Assigned PermissionsCWE-248Uncaught ExceptionCWE-244Improper Clearing of Heap Memory Before Release ('Heap Inspection')CWE-823Use of Out-of-range Pointer OffsetCWE-404Improper Resource Shutdown or ReleaseCWE-444Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling')CWE-138Improper Neutralization of Special ElementsCWE-250Execution with Unnecessary PrivilegesCWE-131Incorrect Calculation of Buffer SizeCWE-190Integer Overflow or WraparoundCWE-772Missing Release of Resource after Effective LifetimeCWE-388-CWE-770Allocation of Resources Without Limits or ThrottlingCWE-120Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')CWE-269Improper Privilege ManagementCWE-119Improper Restriction of Operations within the Bounds of a Memory BufferCWE-787Out-of-bounds WriteCWE-79Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')CWE-80Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS)CWE-788Access of Memory Location After End of Buffer
Risk Scores
CVSS 3.1
6.5/10
Medium · CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Affected Products
| Vendor | Product | Versions | Platforms |
|---|---|---|---|
| Cisco | vers:unknown/* | — | — |
Aliases
CVE-2026-20049CVE-2026-20003CVE-2026-20070CVE-2026-20020CVE-2026-20052CVE-2026-20016CVE-2026-20103CVE-2026-20017CVE-2024-20358CVE-2026-20006CVE-2026-20031CVE-2026-20102CVE-2026-20044CVE-2026-20025CVE-2026-20073CVE-2024-20340CVE-2026-20064CVE-2026-20105CVE-2026-20024CVE-2026-20101CVE-2026-20015CVE-2026-20014CVE-2026-20018CVE-2026-20100CVE-2026-20106CVE-2026-20022CVE-2026-20082CVE-2026-20062CVE-2026-20002CVE-2026-20001CVE-2026-20021CVE-2026-20023CVE-2026-20007CVE-2026-20009CVE-2026-20008CVE-2026-20050CVE-2026-20013CVE-2026-20063CVE-2026-20039CVE-2026-20069
Transitive aliases
GHSA-hvpm-hv6g-6m5cTNCVE-2026-20021VVD-CESS-2026-20021GHSA-4378-qv4j-pgj4GHSA-4q8m-h8wc-99q6CVE-2024-20412GHSA-v4mc-99px-fq68GHSA-qfh3-92rr-375xCISCO-SA-FTD-DND-DOS-BPECG7B7GHSA-x299-q796-x4w4BDU:2024-03233cisco-sa-asaftd-websrvs-dos-X8gNucD2GHSA-mv8w-c2qv-cgrgEUVD-2026-9482CVE-2024-20403BDU:2024-10812GHSA-m287-fgwg-4xpcEUVD-2026-9479VVD-CESS-2026-20082TNCVE-2026-20102cisco-sa-fmc-xss-dhJxQYZsGSD-2024-20300BDU:2024-08631CNVD-2024-44491CISCO-SA-ASAFTD-NSGACL-BYPASS-77XNEASLcisco-sa-ftd-dnd-dos-bpEcg7B7cisco-sa-ftd-snort3ssl-FBEKYXpHCVE-2024-20275CISCO-SA-FMC-XSS-DHJXQYZSCISCO-SA-FMC-FILE-READ-5Q4MQRNGHSA-jgqf-4rxm-w86hGSD-2024-20358cisco-sa-asa-ssh-keybypass-cr5xPUSfEUVD-2026-9476CVE-2024-20374GHSA-m8w7-x24f-68q9CVE-2024-20329cisco-sa-asa-vpn-nyH3fhpCISCO-SA-FMC-SQL-INJECT-2ENMTC8VGHSA-m83r-8rcp-wv5vBDU:2024-08867GHSA-v3gf-g9fc-578xcisco-sa-asaftd-ospf-ZH8PhbSWVVD-CESS-2026-20022VVD-CESS-2026-20070CISCO-SA-FTD-SNORT-BYPASS-RLGGKZVFVVD-CESS-2026-20103GHSA-rmc4-86ph-8m7jcisco-sa-asaftd-bf-dos-vDZhLqrWGHSA-m4qh-qp46-jwg7CVE-2024-20298CISCO-SA-ASAFTD-WEBSRVS-DOS-X8GNUCD2cisco-sa-asaftd-desync-n5AVzEQwGHSA-rgg4-82q2-jw5vcisco-sa-asaftd-saml-LktTrwZPCISCO-SA-ASAFTD-ACL-BYPASS-VVNLNKQFEUVD-2026-9434GHSA-qjf3-5p7q-6r9mCVE-2024-20269GHSA-w38w-gj7f-5836GHSA-rmpg-3w9x-w6prBDU:2024-08814EUVD-2026-9433GHSA-42hx-qv2c-ff49GHSA-v9vp-c2f8-43hhVVD-CESS-2026-20006CVE-2024-20424CVE-2024-20472cisco-sa-fmc-rce-NKhnULJhcisco-sa-asa-vpn-4gYEWMKgVVD-CESS-2026-20031BDU:2024-10829GSD-2024-20403CNVD-2024-44487CISCO-SA-FTDFMC-DIR-TRAV-WERGJHWQcisco-sa-sa-ftd-snort-fw-BCJTZPMuCVE-2024-20384cisco-sa-asa-dos-FCvLD6vRGSD-2024-20260GSD-2024-20384VVD-CESS-2026-20015cisco-sa-clamav-css-Fn4QSZVVD-CESS-2026-20008EUVD-2026-9458GSD-2024-20410CVE-2024-20493cisco-sa-ftd-tls-dos-QXYE5UfyVVD-CESS-2026-20001BDU:2024-10837BDU:2024-08817EUVD-2026-9425BDU:2024-10825WID-SEC-W-2024-0965EUVD-2026-9431CISCO-SA-ASAFTD-LUAINJECT-VESCQGMSVVD-CESS-2026-20044BDU:2024-08557CISCO-SA-FTD-TCP-DOS-RHFQNWRGcisco-sa-ftd-tcp-dos-rHfqnwRgBDU:2024-08847BDU:2024-08576cisco-sa-fmc-file-read-5q4mQRnGHSA-5q5x-hwcj-q6c2EUVD-2026-9477VVD-CESS-2026-20007VVD-CISA-2026-20131GSD-2024-20273GSD-2024-20374CVE-2024-20299VVD-CESS-2026-20101VVD-CESS-2026-20050CVE-2024-20364CVE-2024-20377GSD-2024-20473GHSA-r5hp-h863-8vpxWID-SEC-W-2024-3267GHSA-pp78-fggv-r899cisco-sa-asaftd-persist-lce-vU3ekMJ3CISCO-SA-ASAFTD-OSPF-ZH8PHBSWTNCVE-2026-20014CVE-2024-20402cisco-sa-ftd-statcred-dFC8tXT5GHSA-4fg2-48mj-xwjmVVD-CESS-2026-20073EUVD-2026-9463cisco-sa-onprem-fmc-authbypass-5JPp45V2BDU:2024-10830BDU:2024-10835CVE-2024-20260CVE-2024-20351GHSA-27g3-cp2g-22pwVVD-CESS-2026-20016EUVD-2026-9453GHSA-mj8r-4vp9-fx97CVE-2024-20372BDU:2024-08844BDU:2024-08799GHSA-vq87-vqwh-6mj9EUVD-2026-9439GHSA-xwx2-g284-r7j9GHSA-vv26-9jw2-p445GHSA-p38m-32qc-f4cgGSD-2024-20297cisco-sa-asaftd-xss-yjj7ZjVqcisco-sa-ftd-geoip-bypass-MB4zRDuVVD-CESS-2026-20105CVE-2024-20274GSD-2024-20264GHSA-prx7-jm7p-362ccisco-sa-snort-rf-bypass-OY8f3pnMGSD-2024-20407TNCVE-2026-20106CVE-2024-20341cisco-sa-ftd2100-snort-dos-M9HuMt75cisco-sa-asaftd-luainject-VescqgmScisco-sa-ftd-cmd-inj-mTzGZexfEUVD-2026-9480CVE-2024-20482GHSA-8j6j-jm5x-gjfxCISCO-SA-ASA-VPN-NYH3FHPGHSA-cqv2-qp3h-xq97CISCO-SA-SNORT-BYPASS-PTRY37FXGHSA-9qmm-x6v7-php3WID-SEC-W-2024-3265cisco-sa-asa-tls-CWY6zXBcisco-sa-asa-ssh-rce-gRAuPEUFGSD-2024-20493BDU:2024-08632CVE-2026-20131VVD-CESS-2026-20009GHSA-4jwf-2c3g-hqmjGHSA-rjp2-r49q-cqxhCVE-2024-20410CVE-2024-20339BDU:2024-08575BDU:2024-08890GSD-2024-20341GHSA-7874-r67m-25qhBDU:2024-10815CVE-2024-20407CVE-2024-20388CISCO-SA-ASAFTDVIRTUAL-DOS-MUENGNYRGSD-2024-20342cisco-sa-ftdfmc-dir-trav-wERgjhWqEUVD-2026-9441TNCVE-2026-20015CVE-2024-20264CVE-2024-20471BDU:2024-10827GHSA-gxcq-9p33-rq8fcisco-sa-asaftd-nsgacl-bypass-77XnEAsLCISCO-SA-ASA-FTD-PRIV-ESC-HBS9GNWQGHSA-h526-7r62-gcj9CNVD-2024-43201cisco-sa-asaftd-snmp-dos-7TcnzxTUCVE-2024-20409BDU:2024-10813GHSA-253g-rphr-6h5jBDU:2024-11141CISCO-SA-ASAFTD-CMD-INJ-ZJV8WYSMGHSA-924w-xj2p-25w9VVD-CESS-2026-20003ESB-2026.3678GHSA-chrm-52hv-4ff4GHSA-83hg-vhh4-2hfhVVD-CESS-2026-20069BDU:2024-10834BDU:2024-10832VVD-CESS-2026-20023CVE-2024-20387OPENSUSE-SU-2026:10325-1GHSA-gr7r-qqx6-v859TNCVE-2026-20008EUVD-2026-9443cisco-sa-asaftd-dap-dos-bhEkP7nGHSA-2jcv-f397-c9m8GSD-2024-20364BDU:2024-08846CNVD-2024-44495GSD-2024-20482cisco-sa-asaftd-acl-bypass-VvnLNKqfCISCO-SA-ASAFTD-XSS-YJJ7ZJVQGHSA-fqfv-4r6p-w7m3CNVD-2024-43204CISCO-SA-ASAFTD-BF-DOS-VDZHLQRWBDU:2024-08827EUVD-2026-9430GHSA-rqwm-368v-fp53BDU:2024-03264GHSA-33pq-q8j2-pf3gVVD-CESS-2026-20018cisco-sa-fmc-sql-injection-2qH6CcJdGHSA-r8xj-9pfh-x4pwEUVD-2026-9426GSD-2024-20269CNVD-2024-43203BDU:2024-08855EUVD-2026-9429GSD-2024-20372BDU:2024-08891GSD-2024-20382cisco-sa-asaftd-ikev2-dos-eBueGdEGEUVD-2026-9478CVE-2024-20300BDU:2024-08830BDU:2024-08834BDU:2024-10831CVE-2026-20079WID-SEC-W-2024-3262VVD-CESS-2026-20020TNCVE-2026-20009GSD-2024-20526NCSC-2026-0077CVE-2024-20426GHSA-fqcq-8xcg-f9hhBDU:2024-10811cisco-sa-asaftd-aclbypass-dos-CVxVRSvQGHSA-9hgq-rrv7-j79jBDU:2024-08567cisco-sa-asa-ftd-priv-esc-hBS9gnwqBDU:2024-08566GHSA-3r4j-q266-j9h3TNCVE-2026-20105CNVD-2025-05985CISCO-SA-ASA-SSH-DOS-EEDWU5RMVVD-CESS-2026-20049EUVD-2026-9442GHSA-9688-r3h2-vvjqBDU:2024-08598GSD-2024-20340cisco-sa-asaftd-cmd-inj-ZJV8WysmGHSA-f74q-99mf-mmj8GHSA-f3x2-jxv4-r583GSD-2024-20299CISCO-SA-ASA-VPN-4GYEWMKGEUVD-2026-9455cisco-sa-fmc-cmd-inject-S9ZM4EJfGHSA-x463-pc3r-q5g5EUVD-2026-9444GSD-2024-20481GHSA-jwpj-m256-82wgGSD-2024-20431GSD-2024-20275CISCO-SA-FMC-CMD-INJ-2HBKA97Gcisco-sa-fmc-priv-esc-CMQ4S6m7WID-SEC-W-2024-3269GHSA-f928-7mj9-m8wxCVE-2024-20342GHSA-ch3j-whf9-3xp2CISCO-SA-ASA-SSH-KEYBYPASS-CR5XPUSFcisco-sa-asaftd-persist-rce-FLsNXF4hcisco-sa-fmc-cmd-inj-v3AWDqN7CISCO-SA-FMC-HTML-INJ-NFJEYHXZEUVD-2026-9457GHSA-w6gx-j65f-mmx4CNVD-2024-43202GSD-2024-20386BDU:2024-08896cisco-sa-fmc-xss-infodisc-RL4mJFerCISCO-SA-FMC-PRIV-ESC-CMQ4S6M7TNCVE-2026-20039GSD-2024-20353GHSA-f3vw-6vxw-fwf4GSD-2024-20298CNVD-2024-43206CNVD-2024-44489GSD-2024-20274GSD-2024-20471GHSA-jr5q-32rg-gcqqCVE-2024-20273CNVD-2024-43207cisco-sa-asaftdvirtual-dos-MuenGnYRBDU:2024-10826GHSA-6vh9-9qf6-mvjjVVD-CESS-2026-20024GHSA-jrcg-6c8x-ff3hGSD-2024-20370CERTFR-2024-ALE-007CNVD-2024-44492GHSA-hvrr-v8q8-3r9qEUVD-2024-18196GHSA-4qrp-r28g-j2vfcisco-sa-asa-ssh-dos-eEDWu5RMCISCO-SA-ASAFTD-SAML-LKTTRWZPGSD-2024-20472GHSA-f7qm-mcg6-fhvgGSD-2024-20331CVE-2024-20526EUVD-2026-9428VVD-CESS-2026-20025GHSA-vrw4-xqvw-j7j7cisco-sa-asa-vpn-cZf8gTCNVD-2024-43209CVE-2024-20408VVD-CESS-2026-20039TNCVE-2026-20103ESB-2026.3677VVD-CESS-2026-20131CVE-2024-20330TNCVE-2026-20101GHSA-pvq2-4ff4-p9w6GHSA-4wgv-wwff-cw37VVD-CESS-2026-20064NCSC-2024-0424BDU:2024-11140GHSA-p6rg-m225-p79cEUVD-2026-9436cisco-sa-asaftd-esp-dos-uv7yD8P5GHSA-x599-6m8q-75qpGHSA-hf42-4qwp-gc9rEUVD-2026-9483GHSA-6grm-m6x5-4cvxCISCO-SA-FMC-CMD-INJ-G8AOKNDPGHSA-5xm6-h565-q6mcBDU:2024-10814VVD-CESS-2026-20062cisco-sa-ftd-snort-bypass-rLggKzVFCISCO-SA-ASAFTD-VPN-M9SX6MBCEUVD-2026-9437VVD-CESS-2026-20102CVE-2024-20485GHSA-cp3f-3wc5-j85wCISCO-SA-SNORT-RF-BYPASS-OY8F3PNMcisco-sa-asa-scpcxt-filecpy-rgeP73nEVVD-ANCHORE-2026-20031cisco-sa-asaftd-vpn-dos-SpOFF2ReCISCO-SA-FTD-CMD-INJ-MTZGZEXFGHSA-8pv3-xhwv-wgg4EUVD-2026-9424CISCO-SA-ASAFTD-DESYNC-N5AVZEQWEUVD-2026-9456VVD-CESS-2026-20017BDU:2024-08856CISCO-SA-FMC-SQL-INJ-LOYAFCFQGHSA-99cr-qjpc-34g3EUVD-2026-9438cisco-sa-asaftd-webvpn-dos-hOnB9pH4BDU:2024-03265EUVD-2026-9470EUVD-2026-9472CNVD-2024-44490GHSA-6jcc-w84h-p298GHSA-8vhw-wjxq-h782GHSA-4j6q-qq58-w4v4GSD-2024-20409VVD-NCSC-2024-424BDU:2024-10839CISCO-SA-FTD-GEOIP-BYPASS-MB4ZRDUGHSA-hm6q-48c6-p943EUVD-2026-9435cisco-sa-fmc-sql-inject-2EnmTC8vVVD-CESS-2026-20014VVD-CESS-2026-20013EUVD-2026-9469GHSA-hwhr-j2m2-9887GHSA-69cj-c8c5-j9xjEUVD-2026-9481BDU:2024-10828CVE-2024-20495BDU:2024-08838EUVD-2026-9471VVD-CESS-2026-20106VVD-CESS-2026-20079CVE-2024-20297CVE-2024-20353VVD-CESS-2026-20063GHSA-3j6m-cq99-v646CVE-2024-20494CNVD-2024-43205CVE-2024-20382GHSA-gvjq-f8m6-m457cisco-sa-fmc-html-inj-nfJeYHxzEUVD-2026-9454EUVD-2026-9468CVE-2024-20379VVD-NCSC-2026-76GSD-2024-20415GSD-2024-20379GHSA-pj9f-9jr9-4wm7cisco-sa-fmc-sql-inj-LOYAFcfqGHSA-x2pv-vmm7-rhwrVVD-CESS-2026-20052BDU:2024-08854CVE-2024-20331BDU:2024-08889WID-SEC-W-2024-3261CVE-2024-20359GHSA-2cx5-9j54-v8vqTNCVE-2026-20050GHSA-mh5f-h37q-2qm8BDU:2024-10833CVE-2024-20481cisco-sa-fmc-cmd-inj-g8AOKnDPcisco-sa-asaftd-ikev2-dos-9FgEyHsFBDU:2024-10838TNCVE-2026-20049BDU:2024-11132BDU:2024-08881EUVD-2026-9440VVD-CESS-2026-20100CVE-2024-20386CVE-2024-20431VVD-CESS-2026-20002cisco-sa-fmc-cmd-inj-2HBkA97GCVE-2024-20415CVE-2024-20473BDU:2024-08837CISCO-SA-FMC-SQL-INJECTION-2QH6CCJDCVE-2024-20268GHSA-hr33-3275-hjcvGHSA-c9c2-73hm-242hcisco-sa-asaftd-webvpn-xss-uwjc4HRCVE-2024-20370EUVD-2026-9432TNCVE-2026-20013GHSA-9pj9-8qr7-5x38cisco-sa-snort-bypass-PTry37fXBDU:2024-08841cisco-sa-asaftd-vpn-m9sx6MbCGHSA-r229-mj76-g2qx
References
Browse GCVE Records
100 records in the GCVE database · Updated April 16, 2026
No matching records found.
Explore Further
Investigate this vulnerability in the interactive console or download the raw GCVE record.