VDB

GCVE-VVD-NCSC-2026-77

GCVE-VVD-NCSC-2026-77
Advisory PublishedCVSS 6.5/10
Vulnetix · Advisory published March 5, 2026
Multiple vulnerabilities in Cisco products, including an SQL injection flaw in Cisco Secure Firewall Management Center, allow authenticated users or remote attackers to perform actions such as SQL injection, denial of service, privilege escalation, remote code execution, and information disclosure.

Weaknesses (CWE)

CWE-89Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')CWE-78Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')CWE-330Use of Insufficiently Random ValuesCWE-20Improper Input ValidationCWE-284Improper Access ControlCWE-27Path Traversal: 'dir/../../filename'CWE-401Missing Release of Memory after Effective LifetimeCWE-279Incorrect Execution-Assigned PermissionsCWE-248Uncaught ExceptionCWE-244Improper Clearing of Heap Memory Before Release ('Heap Inspection')CWE-823Use of Out-of-range Pointer OffsetCWE-404Improper Resource Shutdown or ReleaseCWE-444Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling')CWE-138Improper Neutralization of Special ElementsCWE-250Execution with Unnecessary PrivilegesCWE-131Incorrect Calculation of Buffer SizeCWE-190Integer Overflow or WraparoundCWE-772Missing Release of Resource after Effective LifetimeCWE-388-CWE-770Allocation of Resources Without Limits or ThrottlingCWE-120Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')CWE-269Improper Privilege ManagementCWE-119Improper Restriction of Operations within the Bounds of a Memory BufferCWE-787Out-of-bounds WriteCWE-79Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')CWE-80Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS)CWE-788Access of Memory Location After End of Buffer

Risk Scores

CVSS 3.1
6.5/10
Medium · CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

Affected Products

VendorProductVersionsPlatforms
Ciscovers:unknown/*

Aliases

Transitive aliases

GHSA-hvpm-hv6g-6m5cTNCVE-2026-20021VVD-CESS-2026-20021GHSA-4378-qv4j-pgj4GHSA-4q8m-h8wc-99q6CVE-2024-20412GHSA-v4mc-99px-fq68GHSA-qfh3-92rr-375xCISCO-SA-FTD-DND-DOS-BPECG7B7GHSA-x299-q796-x4w4BDU:2024-03233cisco-sa-asaftd-websrvs-dos-X8gNucD2GHSA-mv8w-c2qv-cgrgEUVD-2026-9482CVE-2024-20403BDU:2024-10812GHSA-m287-fgwg-4xpcEUVD-2026-9479VVD-CESS-2026-20082TNCVE-2026-20102cisco-sa-fmc-xss-dhJxQYZsGSD-2024-20300BDU:2024-08631CNVD-2024-44491CISCO-SA-ASAFTD-NSGACL-BYPASS-77XNEASLcisco-sa-ftd-dnd-dos-bpEcg7B7cisco-sa-ftd-snort3ssl-FBEKYXpHCVE-2024-20275CISCO-SA-FMC-XSS-DHJXQYZSCISCO-SA-FMC-FILE-READ-5Q4MQRNGHSA-jgqf-4rxm-w86hGSD-2024-20358cisco-sa-asa-ssh-keybypass-cr5xPUSfEUVD-2026-9476CVE-2024-20374GHSA-m8w7-x24f-68q9CVE-2024-20329cisco-sa-asa-vpn-nyH3fhpCISCO-SA-FMC-SQL-INJECT-2ENMTC8VGHSA-m83r-8rcp-wv5vBDU:2024-08867GHSA-v3gf-g9fc-578xcisco-sa-asaftd-ospf-ZH8PhbSWVVD-CESS-2026-20022VVD-CESS-2026-20070CISCO-SA-FTD-SNORT-BYPASS-RLGGKZVFVVD-CESS-2026-20103GHSA-rmc4-86ph-8m7jcisco-sa-asaftd-bf-dos-vDZhLqrWGHSA-m4qh-qp46-jwg7CVE-2024-20298CISCO-SA-ASAFTD-WEBSRVS-DOS-X8GNUCD2cisco-sa-asaftd-desync-n5AVzEQwGHSA-rgg4-82q2-jw5vcisco-sa-asaftd-saml-LktTrwZPCISCO-SA-ASAFTD-ACL-BYPASS-VVNLNKQFEUVD-2026-9434GHSA-qjf3-5p7q-6r9mCVE-2024-20269GHSA-w38w-gj7f-5836GHSA-rmpg-3w9x-w6prBDU:2024-08814EUVD-2026-9433GHSA-42hx-qv2c-ff49GHSA-v9vp-c2f8-43hhVVD-CESS-2026-20006CVE-2024-20424CVE-2024-20472cisco-sa-fmc-rce-NKhnULJhcisco-sa-asa-vpn-4gYEWMKgVVD-CESS-2026-20031BDU:2024-10829GSD-2024-20403CNVD-2024-44487CISCO-SA-FTDFMC-DIR-TRAV-WERGJHWQcisco-sa-sa-ftd-snort-fw-BCJTZPMuCVE-2024-20384cisco-sa-asa-dos-FCvLD6vRGSD-2024-20260GSD-2024-20384VVD-CESS-2026-20015cisco-sa-clamav-css-Fn4QSZVVD-CESS-2026-20008EUVD-2026-9458GSD-2024-20410CVE-2024-20493cisco-sa-ftd-tls-dos-QXYE5UfyVVD-CESS-2026-20001BDU:2024-10837BDU:2024-08817EUVD-2026-9425BDU:2024-10825WID-SEC-W-2024-0965EUVD-2026-9431CISCO-SA-ASAFTD-LUAINJECT-VESCQGMSVVD-CESS-2026-20044BDU:2024-08557CISCO-SA-FTD-TCP-DOS-RHFQNWRGcisco-sa-ftd-tcp-dos-rHfqnwRgBDU:2024-08847BDU:2024-08576cisco-sa-fmc-file-read-5q4mQRnGHSA-5q5x-hwcj-q6c2EUVD-2026-9477VVD-CESS-2026-20007VVD-CISA-2026-20131GSD-2024-20273GSD-2024-20374CVE-2024-20299VVD-CESS-2026-20101VVD-CESS-2026-20050CVE-2024-20364CVE-2024-20377GSD-2024-20473GHSA-r5hp-h863-8vpxWID-SEC-W-2024-3267GHSA-pp78-fggv-r899cisco-sa-asaftd-persist-lce-vU3ekMJ3CISCO-SA-ASAFTD-OSPF-ZH8PHBSWTNCVE-2026-20014CVE-2024-20402cisco-sa-ftd-statcred-dFC8tXT5GHSA-4fg2-48mj-xwjmVVD-CESS-2026-20073EUVD-2026-9463cisco-sa-onprem-fmc-authbypass-5JPp45V2BDU:2024-10830BDU:2024-10835CVE-2024-20260CVE-2024-20351GHSA-27g3-cp2g-22pwVVD-CESS-2026-20016EUVD-2026-9453GHSA-mj8r-4vp9-fx97CVE-2024-20372BDU:2024-08844BDU:2024-08799GHSA-vq87-vqwh-6mj9EUVD-2026-9439GHSA-xwx2-g284-r7j9GHSA-vv26-9jw2-p445GHSA-p38m-32qc-f4cgGSD-2024-20297cisco-sa-asaftd-xss-yjj7ZjVqcisco-sa-ftd-geoip-bypass-MB4zRDuVVD-CESS-2026-20105CVE-2024-20274GSD-2024-20264GHSA-prx7-jm7p-362ccisco-sa-snort-rf-bypass-OY8f3pnMGSD-2024-20407TNCVE-2026-20106CVE-2024-20341cisco-sa-ftd2100-snort-dos-M9HuMt75cisco-sa-asaftd-luainject-VescqgmScisco-sa-ftd-cmd-inj-mTzGZexfEUVD-2026-9480CVE-2024-20482GHSA-8j6j-jm5x-gjfxCISCO-SA-ASA-VPN-NYH3FHPGHSA-cqv2-qp3h-xq97CISCO-SA-SNORT-BYPASS-PTRY37FXGHSA-9qmm-x6v7-php3WID-SEC-W-2024-3265cisco-sa-asa-tls-CWY6zXBcisco-sa-asa-ssh-rce-gRAuPEUFGSD-2024-20493BDU:2024-08632CVE-2026-20131VVD-CESS-2026-20009GHSA-4jwf-2c3g-hqmjGHSA-rjp2-r49q-cqxhCVE-2024-20410CVE-2024-20339BDU:2024-08575BDU:2024-08890GSD-2024-20341GHSA-7874-r67m-25qhBDU:2024-10815CVE-2024-20407CVE-2024-20388CISCO-SA-ASAFTDVIRTUAL-DOS-MUENGNYRGSD-2024-20342cisco-sa-ftdfmc-dir-trav-wERgjhWqEUVD-2026-9441TNCVE-2026-20015CVE-2024-20264CVE-2024-20471BDU:2024-10827GHSA-gxcq-9p33-rq8fcisco-sa-asaftd-nsgacl-bypass-77XnEAsLCISCO-SA-ASA-FTD-PRIV-ESC-HBS9GNWQGHSA-h526-7r62-gcj9CNVD-2024-43201cisco-sa-asaftd-snmp-dos-7TcnzxTUCVE-2024-20409BDU:2024-10813GHSA-253g-rphr-6h5jBDU:2024-11141CISCO-SA-ASAFTD-CMD-INJ-ZJV8WYSMGHSA-924w-xj2p-25w9VVD-CESS-2026-20003ESB-2026.3678GHSA-chrm-52hv-4ff4GHSA-83hg-vhh4-2hfhVVD-CESS-2026-20069BDU:2024-10834BDU:2024-10832VVD-CESS-2026-20023CVE-2024-20387OPENSUSE-SU-2026:10325-1GHSA-gr7r-qqx6-v859TNCVE-2026-20008EUVD-2026-9443cisco-sa-asaftd-dap-dos-bhEkP7nGHSA-2jcv-f397-c9m8GSD-2024-20364BDU:2024-08846CNVD-2024-44495GSD-2024-20482cisco-sa-asaftd-acl-bypass-VvnLNKqfCISCO-SA-ASAFTD-XSS-YJJ7ZJVQGHSA-fqfv-4r6p-w7m3CNVD-2024-43204CISCO-SA-ASAFTD-BF-DOS-VDZHLQRWBDU:2024-08827EUVD-2026-9430GHSA-rqwm-368v-fp53BDU:2024-03264GHSA-33pq-q8j2-pf3gVVD-CESS-2026-20018cisco-sa-fmc-sql-injection-2qH6CcJdGHSA-r8xj-9pfh-x4pwEUVD-2026-9426GSD-2024-20269CNVD-2024-43203BDU:2024-08855EUVD-2026-9429GSD-2024-20372BDU:2024-08891GSD-2024-20382cisco-sa-asaftd-ikev2-dos-eBueGdEGEUVD-2026-9478CVE-2024-20300BDU:2024-08830BDU:2024-08834BDU:2024-10831CVE-2026-20079WID-SEC-W-2024-3262VVD-CESS-2026-20020TNCVE-2026-20009GSD-2024-20526NCSC-2026-0077CVE-2024-20426GHSA-fqcq-8xcg-f9hhBDU:2024-10811cisco-sa-asaftd-aclbypass-dos-CVxVRSvQGHSA-9hgq-rrv7-j79jBDU:2024-08567cisco-sa-asa-ftd-priv-esc-hBS9gnwqBDU:2024-08566GHSA-3r4j-q266-j9h3TNCVE-2026-20105CNVD-2025-05985CISCO-SA-ASA-SSH-DOS-EEDWU5RMVVD-CESS-2026-20049EUVD-2026-9442GHSA-9688-r3h2-vvjqBDU:2024-08598GSD-2024-20340cisco-sa-asaftd-cmd-inj-ZJV8WysmGHSA-f74q-99mf-mmj8GHSA-f3x2-jxv4-r583GSD-2024-20299CISCO-SA-ASA-VPN-4GYEWMKGEUVD-2026-9455cisco-sa-fmc-cmd-inject-S9ZM4EJfGHSA-x463-pc3r-q5g5EUVD-2026-9444GSD-2024-20481GHSA-jwpj-m256-82wgGSD-2024-20431GSD-2024-20275CISCO-SA-FMC-CMD-INJ-2HBKA97Gcisco-sa-fmc-priv-esc-CMQ4S6m7WID-SEC-W-2024-3269GHSA-f928-7mj9-m8wxCVE-2024-20342GHSA-ch3j-whf9-3xp2CISCO-SA-ASA-SSH-KEYBYPASS-CR5XPUSFcisco-sa-asaftd-persist-rce-FLsNXF4hcisco-sa-fmc-cmd-inj-v3AWDqN7CISCO-SA-FMC-HTML-INJ-NFJEYHXZEUVD-2026-9457GHSA-w6gx-j65f-mmx4CNVD-2024-43202GSD-2024-20386BDU:2024-08896cisco-sa-fmc-xss-infodisc-RL4mJFerCISCO-SA-FMC-PRIV-ESC-CMQ4S6M7TNCVE-2026-20039GSD-2024-20353GHSA-f3vw-6vxw-fwf4GSD-2024-20298CNVD-2024-43206CNVD-2024-44489GSD-2024-20274GSD-2024-20471GHSA-jr5q-32rg-gcqqCVE-2024-20273CNVD-2024-43207cisco-sa-asaftdvirtual-dos-MuenGnYRBDU:2024-10826GHSA-6vh9-9qf6-mvjjVVD-CESS-2026-20024GHSA-jrcg-6c8x-ff3hGSD-2024-20370CERTFR-2024-ALE-007CNVD-2024-44492GHSA-hvrr-v8q8-3r9qEUVD-2024-18196GHSA-4qrp-r28g-j2vfcisco-sa-asa-ssh-dos-eEDWu5RMCISCO-SA-ASAFTD-SAML-LKTTRWZPGSD-2024-20472GHSA-f7qm-mcg6-fhvgGSD-2024-20331CVE-2024-20526EUVD-2026-9428VVD-CESS-2026-20025GHSA-vrw4-xqvw-j7j7cisco-sa-asa-vpn-cZf8gTCNVD-2024-43209CVE-2024-20408VVD-CESS-2026-20039TNCVE-2026-20103ESB-2026.3677VVD-CESS-2026-20131CVE-2024-20330TNCVE-2026-20101GHSA-pvq2-4ff4-p9w6GHSA-4wgv-wwff-cw37VVD-CESS-2026-20064NCSC-2024-0424BDU:2024-11140GHSA-p6rg-m225-p79cEUVD-2026-9436cisco-sa-asaftd-esp-dos-uv7yD8P5GHSA-x599-6m8q-75qpGHSA-hf42-4qwp-gc9rEUVD-2026-9483GHSA-6grm-m6x5-4cvxCISCO-SA-FMC-CMD-INJ-G8AOKNDPGHSA-5xm6-h565-q6mcBDU:2024-10814VVD-CESS-2026-20062cisco-sa-ftd-snort-bypass-rLggKzVFCISCO-SA-ASAFTD-VPN-M9SX6MBCEUVD-2026-9437VVD-CESS-2026-20102CVE-2024-20485GHSA-cp3f-3wc5-j85wCISCO-SA-SNORT-RF-BYPASS-OY8F3PNMcisco-sa-asa-scpcxt-filecpy-rgeP73nEVVD-ANCHORE-2026-20031cisco-sa-asaftd-vpn-dos-SpOFF2ReCISCO-SA-FTD-CMD-INJ-MTZGZEXFGHSA-8pv3-xhwv-wgg4EUVD-2026-9424CISCO-SA-ASAFTD-DESYNC-N5AVZEQWEUVD-2026-9456VVD-CESS-2026-20017BDU:2024-08856CISCO-SA-FMC-SQL-INJ-LOYAFCFQGHSA-99cr-qjpc-34g3EUVD-2026-9438cisco-sa-asaftd-webvpn-dos-hOnB9pH4BDU:2024-03265EUVD-2026-9470EUVD-2026-9472CNVD-2024-44490GHSA-6jcc-w84h-p298GHSA-8vhw-wjxq-h782GHSA-4j6q-qq58-w4v4GSD-2024-20409VVD-NCSC-2024-424BDU:2024-10839CISCO-SA-FTD-GEOIP-BYPASS-MB4ZRDUGHSA-hm6q-48c6-p943EUVD-2026-9435cisco-sa-fmc-sql-inject-2EnmTC8vVVD-CESS-2026-20014VVD-CESS-2026-20013EUVD-2026-9469GHSA-hwhr-j2m2-9887GHSA-69cj-c8c5-j9xjEUVD-2026-9481BDU:2024-10828CVE-2024-20495BDU:2024-08838EUVD-2026-9471VVD-CESS-2026-20106VVD-CESS-2026-20079CVE-2024-20297CVE-2024-20353VVD-CESS-2026-20063GHSA-3j6m-cq99-v646CVE-2024-20494CNVD-2024-43205CVE-2024-20382GHSA-gvjq-f8m6-m457cisco-sa-fmc-html-inj-nfJeYHxzEUVD-2026-9454EUVD-2026-9468CVE-2024-20379VVD-NCSC-2026-76GSD-2024-20415GSD-2024-20379GHSA-pj9f-9jr9-4wm7cisco-sa-fmc-sql-inj-LOYAFcfqGHSA-x2pv-vmm7-rhwrVVD-CESS-2026-20052BDU:2024-08854CVE-2024-20331BDU:2024-08889WID-SEC-W-2024-3261CVE-2024-20359GHSA-2cx5-9j54-v8vqTNCVE-2026-20050GHSA-mh5f-h37q-2qm8BDU:2024-10833CVE-2024-20481cisco-sa-fmc-cmd-inj-g8AOKnDPcisco-sa-asaftd-ikev2-dos-9FgEyHsFBDU:2024-10838TNCVE-2026-20049BDU:2024-11132BDU:2024-08881EUVD-2026-9440VVD-CESS-2026-20100CVE-2024-20386CVE-2024-20431VVD-CESS-2026-20002cisco-sa-fmc-cmd-inj-2HBkA97GCVE-2024-20415CVE-2024-20473BDU:2024-08837CISCO-SA-FMC-SQL-INJECTION-2QH6CCJDCVE-2024-20268GHSA-hr33-3275-hjcvGHSA-c9c2-73hm-242hcisco-sa-asaftd-webvpn-xss-uwjc4HRCVE-2024-20370EUVD-2026-9432TNCVE-2026-20013GHSA-9pj9-8qr7-5x38cisco-sa-snort-bypass-PTry37fXBDU:2024-08841cisco-sa-asaftd-vpn-m9sx6MbCGHSA-r229-mj76-g2qx

References

advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory

Browse GCVE Records

100 records in the GCVE database · Updated April 16, 2026

No matching records found.

Explore Further

Investigate this vulnerability in the interactive console or download the raw GCVE record.

$ Console Community · 100/wk Open console ›