Known vulnerabilities in Cisco Secure Firewall Management Center (formerly Firepower Management Center, FMC) - page 7

Software CPE: cpe:2.3:a:cisco_systems:cisco_firepower_management_center:*:*:*:*:*:*:*:*
Total vulnerabilities: 160
Public exploits: 4
Known exploited (KEV): 3
Highest CVSSv4 Score: 10

Breakdown by Severity Chart

Severity distribution of vulnerabilities affecting Cisco Secure Firewall Management Center (formerly Firepower Management Center, FMC) Cisco Secure Firewall Management Center (formerly Firepower Management Center, FMC) is affected by 160 known vulnerabilities: 2 critical, 19 high, 42 medium, 97 low Critical High Medium Low

Vulnerabilities (160)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU21627 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVE-2019-12691
CWE-22 Low
No
No
6.2.3 08.10.2019 SB2019100805
#VU21626 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CVE-2019-12690
CWE-78 Medium
No
No
6.1.0.7, 6.2.0.6, 6.2.2.3, 6.2.3 08.10.2019 SB2019100805
#VU21625 - Improper input validation
CVE-2019-12689
CWE-20 Medium
No
No
6.2.2.2, 6.2.3 08.10.2019 SB2019100805
#VU21623 - Memory corruption
CVE-2019-12688
CWE-119 High
No
No
6.2.3 08.10.2019 SB2019100805
#VU21622 - Memory corruption
CVE-2019-12687
CWE-119 High
No
No
6.2.2.3, 6.2.3 08.10.2019 SB2019100805
#VU21621 - Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
CVE-2019-12686
CWE-89 High
No
No
6.2.3.11, 6.4.0 08.10.2019 SB2019100805
#VU21620 - Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
CVE-2019-12685
CWE-89 High
No
No
6.3.0 08.10.2019 SB2019100805
#VU21619 - Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
CVE-2019-12683
CWE-89 High
No
No
6.1.0.7, 6.2.0.5, 6.2.2.2, 6.2.3 08.10.2019 SB2019100805
#VU21618 - Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
CVE-2019-12684
CWE-89 High
No
No
6.2.0.6, 6.2.2.3, 6.2.3 08.10.2019 SB2019100805
#VU21617 - Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
CVE-2019-12682
CWE-89 High
No
No
6.2.3 08.10.2019 SB2019100805
#VU21616 - Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
CVE-2019-12681
CWE-89 High
No
No
6.1.0.7, 6.2.0.6, 6.2.2.3, 6.2.3 08.10.2019 SB2019100805
#VU17428 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2019-1671
CWE-79 Low
No
No
- 07.02.2019 SB2019020709
#VU17193 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2019-1642
CWE-79 Low
Available
No
6.2.3.7, 6.3.0 23.01.2019 SB2019012409
#VU16930 - Resource exhaustion
CVE-2018-15458
CWE-400 Low
No
No
6.2.3.7 09.01.2019 SB2019011012
#VU15769 - Memory corruption
CVE-2018-15443
CWE-119 Low
No
No
6.2.3.6 07.11.2018 SB2018110815
#VU13857 - Resource exhaustion
CVE-2018-0370
CWE-400 Low
No
No
6.2.2.3, 6.2.3 13.07.2018 SB2018071306
#VU13856 - Improper input validation
CVE-2018-0385
CWE-20 Low
No
No
6.2.2.4 11.07.2018 SB2018071306
#VU13410 - Cross-Site Request Forgery (CSRF)
CVE-2018-0365
CWE-352 Low
No
No
- 21.06.2018 SB2018062108
#VU12792 - Data Handling
CVE-2018-0297
CWE-19 Low
No
No
- 17.05.2018 SB2018051718
#VU12383 - Improper input validation
CVE-2018-0281
CWE-20 Low
No
No
- 07.05.2018 SB2018050708


Showing elements 121 - 140 out of 160