Known vulnerabilities in Cisco Secure Firewall Management Center (formerly Firepower Management Center, FMC) - page 2

Software CPE: cpe:2.3:a:cisco_systems:cisco_firepower_management_center:*:*:*:*:*:*:*:*
Total vulnerabilities: 148
Public exploits: 3
Known exploited (KEV): 2
Highest CVSSv4 Score: 10

Breakdown by Severity Chart

Severity distribution of vulnerabilities affecting Cisco Secure Firewall Management Center (formerly Firepower Management Center, FMC) Cisco Secure Firewall Management Center (formerly Firepower Management Center, FMC) is affected by 148 known vulnerabilities: 2 critical, 16 high, 34 medium, 96 low Critical High Medium Low

Vulnerabilities (148)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU99319 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2024-20274
CWE-79 Low
No
No
7.0.6.2, 7.2.6, 7.4.2 24.10.2024 SB2024102421
#VU99318 - Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
CVE-2024-20340
CWE-89 Medium
No
No
7.0.6.3, 7.2.9, 7.4.2.1, 7.6.0 24.10.2024 SB2024102420
#VU99317 - Exposure of sensitive information to an unauthorized actor
CVE-2024-20388
CWE-200 Medium
No
No
7.0.6.3, 7.2.9, 7.4.2, 7.4.2.1, 7.6.0 24.10.2024 SB2024102419
#VU99316 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2024-20387
CWE-79 Low
No
No
7.0.6.3, 7.2.9, 7.4.2, 7.4.2.1, 7.6.0 24.10.2024 SB2024102419
#VU99315 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2024-20377
CWE-79 Low
No
No
7.2.9, 7.4.2, 7.4.2.1, 7.6.0 24.10.2024 SB2024102419
#VU99314 - Incorrect Authorization
CVE-2024-20482
CWE-863 Medium
No
No
7.2.9, 7.4.0, 7.4.1, 7.4.1.1, 7.4.2, 7.4.2.1, 7.6.0 24.10.2024 SB2024102415
#VU99313 - Improper Privilege Management
CVE-2024-20374
CWE-269 Low
No
No
7.0.6.3, 7.2.9, 7.4.2, 7.4.2.1, 7.6.0 24.10.2024 SB2024102413
#VU99311 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVE-2024-20379
CWE-22 Medium
No
No
7.4.2, 7.4.2.1, 7.6.0 24.10.2024 SB2024102412
#VU99310 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CVE-2024-20275
CWE-78 Low
No
No
7.2.6, 7.2.7, 7.2.8, 7.2.8.1, 7.2.9, 7.4.2, 7.4.2.1, 7.6.0 24.10.2024 SB2024102411
#VU99309 - Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
CVE-2024-20473
CWE-89 Low
No
No
7.4.2, 7.4.2.1, 7.6.0 24.10.2024 SB2024102410
#VU99308 - Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
CVE-2024-20472
CWE-89 Low
No
No
7.4.2, 7.4.2.1, 7.6.0 24.10.2024 SB2024102410
#VU99307 - Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
CVE-2024-20471
CWE-89 Low
No
No
7.0.6.3, 7.2.9, 7.4.2, 7.4.2.1, 7.6.0 24.10.2024 SB2024102410
#VU99302 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2024-20386
CWE-79 Low
No
No
7.0.6.3, 7.2.9, 7.4.2, 7.4.2.1, 7.6.0 24.10.2024 SB2024102408
#VU99301 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2024-20372
CWE-79 Low
No
No
7.0.6.3, 7.2.9, 7.4.2, 7.4.2.1 24.10.2024 SB2024102408
#VU99300 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2024-20364
CWE-79 Low
No
No
7.0.6.3, 7.2.9, 7.4.2, 7.4.2.1, 7.6.0 24.10.2024 SB2024102408
#VU99299 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2024-20300
CWE-79 Low
No
No
6.4.0.18, 7.0.6.2, 7.0.6.3, 7.2.6, 7.2.7, 7.2.8, 7.2.8.1, 7.2.9, 7.4.2, 7.4.2.1, 7.6.0 24.10.2024 SB2024102408
#VU99298 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2024-20298
CWE-79 Low
No
No
7.4.2, 7.4.2.1, 7.6.0 24.10.2024 SB2024102408
#VU99297 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2024-20273
CWE-79 Low
No
No
6.4.0.18, 7.0.6.2, 7.0.6.3, 7.2.6, 7.2.7, 7.2.8, 7.2.8.1, 7.2.9, 7.4.1, 7.4.1.1, 7.4.2, 7.4.2.1, 7.6.0 24.10.2024 SB2024102408
#VU99296 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2024-20269
CWE-79 Low
No
No
6.4.0.18, 7.0.6.2, 7.0.6.3, 7.2.6, 7.2.7, 7.2.8, 7.2.8.1, 7.2.9, 7.4.1, 7.4.1.1, 7.4.2, 7.4.2.1, 7.6.0 24.10.2024 SB2024102408
#VU99295 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2024-20264
CWE-79 Low
No
No
7.2.6, 7.2.7, 7.2.8, 7.2.8.1, 7.2.9, 7.3.0, 7.3.1, 7.3.1.1, 7.3.1.2, 7.4.0, 7.4.1, 7.4.1.1, 7.4.2, 7.4.2.1, 7.6.0 24.10.2024 SB2024102408


Showing elements 21 - 40 out of 148