Known vulnerabilities in Cisco Secure Firewall Management Center (formerly Firepower Management Center, FMC) - page 3

Software CPE: cpe:2.3:a:cisco_systems:cisco_firepower_management_center:*:*:*:*:*:*:*:*
Total vulnerabilities: 148
Public exploits: 3
Known exploited (KEV): 2
Highest CVSSv4 Score: 10

Breakdown by Severity Chart

Severity distribution of vulnerabilities affecting Cisco Secure Firewall Management Center (formerly Firepower Management Center, FMC) Cisco Secure Firewall Management Center (formerly Firepower Management Center, FMC) is affected by 148 known vulnerabilities: 2 critical, 16 high, 34 medium, 96 low Critical High Medium Low

Vulnerabilities (148)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU99306 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2024-20415
CWE-79 Low
No
No
-, 4.10.3, 5.2.0, 5.3.0, 5.3.0.3, 5.3.1, 5.3.1.2, 5.4.0, 5.4.0.1, 5.4.1, 5.4.1.6, 6.0.0, 6.0.1, 6.0.1.3, 6.1.0, 6.1.0.1, 6.1.0.2, 6.1.0.5, 6.1.0.6, 6.1.0.7, 6.2.0, 6.2.0.2, 6.2.0.3, 6.2.0.4, 6.2.0.5, 6.2.0.6, 6.2.1, 6.2.2, 6.2.2.1, 6.2.2.2, 6.2.2.3, 6.2.2.4, 6.2.2.5, 6.2.3, 6.2.3.1, 6.2.3.2, 6.2.3.3, 6.2.3.4, 6.2.3.5, 6.2.3.6, 6.2.3.7, 6.2.3.8, 6.2.3.9, 6.2.3.10, 6.2.3.11, 6.2.3.12, 6.2.3.13, 6.2.3.14, 6.2.3.15, 6.2.3.16, 6.2.3.17, 6.2.3.18, 6.3.0, 6.3.0.2, 6.4.0, 6.4.0.1, 6.4.0.2, 6.4.0.3, 6.4.0.4, 6.4.0.5, 6.4.0.6, 6.4.0.7, 6.4.0.8, 6.4.0.9, 6.4.0.10, 6.4.0.11, 6.4.0.12, 6.4.0.13, 6.4.0.14, 6.4.0.15, 6.4.0.16, 6.4.0.17, 6.4.0.18, 6.5.0, 6.5.2.0, 6.6.0, 6.6.0.1, 6.6.1, 6.6.3, 6.6.4, 6.6.5, 6.6.5.1, 6.6.5.2, 6.6.7, 6.6.7.1, 6.6.7.2, 6.7.0, 6.7.0.1, 6.7.0.2, 6.7.0.3, 7.0.0, 7.0.0.1, 7.0.1, 7.0.1.1, 7.0.2, 7.0.2.1, 7.0.3, 7.0.4, 7.0.5, 7.0.6, 7.0.6.1, 7.0.6.2, 7.0.6.3, 7.1, 7.1.0, 7.1.0.1, 7.1.0.2, 7.1.0.3, 7.1.1, 7.2.0, 7.2.0.1, 7.2.1, 7.2.2, 7.2.3, 7.2.3.1, 7.2.4, 7.2.4.1, 7.2.5, 7.2.5.1, 7.2.5.2, 7.2.6, 7.2.7, 7.2.8, 7.2.8.1, 7.2.9, 7.3.0, 7.3.1, 7.3.1.1, 7.3.1.2, 7.4.0, 7.4.1, 7.4.1.1, 7.4.2, 7.4.2.1, 7.6.0 24.10.2024 SB2024102408
#VU99305 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2024-20410
CWE-79 Low
No
No
7.0.6.3, 7.2.9, 7.4.2, 7.4.2.1, 7.6.0 24.10.2024 SB2024102408
#VU99304 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2024-20409
CWE-79 Low
No
No
7.0.6.3, 7.2.9, 7.4.2.1, 7.6.0 24.10.2024 SB2024102408
#VU99303 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2024-20403
CWE-79 Low
No
No
7.0.6.3, 7.2.9, 7.4.2.1, 7.6.0 24.10.2024 SB2024102408
#VU99292 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CVE-2024-20424
CWE-78 High
No
No
7.0.6.3, 7.2.9, 7.4.2.1, 7.6.0 24.10.2024 SB2024102401
#VU89832 - Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
CVE-2024-20360
CWE-89 Medium
No
No
7.0.6.1, 7.0.6.2, 7.2.5.1, 7.2.5.2, 7.2.6, 7.2.7, 7.4.0, 7.4.1, 7.4.1.1 27.05.2024 SB2024052719
#VU89831 - Permissions, Privileges, and Access Controls
CVE-2024-20361
CWE-264 Medium
No
No
7.2.4, 7.2.4.1, 7.2.5, 7.2.5.1, 7.2.5.2, 7.2.6, 7.2.7, 7.3.1.1, 7.3.1.2, 7.4.0, 7.4.1, 7.4.1.1 27.05.2024 SB2024052717
#VU82685 - Exposure of sensitive information to an unauthorized actor
CVE-2023-20114
CWE-200 Medium
No
No
7.0.6, 7.2.4 02.11.2023 SB2023110243
#VU82683 - Improper input validation
CVE-2023-20155
CWE-20 Medium
No
No
6.4.0.17, 7.0.6, 7.2.4 02.11.2023 SB2023110240
#VU82674 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CVE-2023-20063
CWE-78 Low
No
No
7.0.6, 7.2.4, 7.3.0 02.11.2023 SB2023110218
#VU82673 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CVE-2023-20048
CWE-78 Medium
Available
No
6.4.0.17, 7.0.6, 7.2.4 02.11.2023 SB2023110217
#VU82672 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CVE-2023-20220
CWE-78 Low
No
No
6.4.0.17, 7.0.6, 7.2.5 02.11.2023 SB2023110216
#VU82671 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CVE-2023-20219
CWE-78 Low
No
No
7.0.6, 7.2.4.1, 7.2.5 02.11.2023 SB2023110216
#VU82668 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2023-20206
CWE-79 Low
No
No
- 02.11.2023 SB2023110204
#VU82667 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2023-20074
CWE-79 Low
No
No
6.4.0.17, 7.0.6, 7.2.4.1 02.11.2023 SB2023110204
#VU82666 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2023-20041
CWE-79 Low
No
No
6.4.0.17, 7.0.6, 7.2.4, 7.3.0 02.11.2023 SB2023110204
#VU82665 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2023-20005
CWE-79 Low
No
No
7.0.6, 7.2.4, 7.3.0 02.11.2023 SB2023110204
#VU69242 - Resource exhaustion
CVE-2022-20854
CWE-400 Medium
No
No
6.6.7, 7.1.0 11.11.2022 SB2022111115
#VU69237 -
CVE-2022-20941
Medium
No
No
7.2.0 11.11.2022 SB2022111109
#VU69236 - Improper Restriction of XML External Entity Reference ('XXE')
CVE-2022-20938
CWE-611 Low
No
No
6.6.7, 7.2.0 11.11.2022 SB2022111109


Showing elements 41 - 60 out of 148