Input validation error in Cisco Secure Firewall Management Center (formerly Firepower Management Center, FMC) - CVE-2020-3307
Published: May 11, 2020
Vulnerability identifier: #VU27684
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2020-3307
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to write arbitrary entries to the log file on the target device.
The vulnerability exists due to insufficient validation of user-supplied input in the web UI. A remote attacker can send a specially crafted HTTP request and send incorrect information to the system log on the affected system.
Affected software
Cisco Secure Firewall Management Center (formerly Firepower Management Center, FMC)
How to mitigate CVE-2020-3307
Install updates from vendor's website.
Cisco Secure Firewall Management Center (formerly Firepower Management Center, FMC) - update to 6.3.0.2