Input validation error in Cisco Secure Firewall Management Center (formerly Firepower Management Center, FMC) - CVE-2020-3307

 

Input validation error in Cisco Secure Firewall Management Center (formerly Firepower Management Center, FMC) - CVE-2020-3307

Published: May 11, 2020


Vulnerability identifier: #VU27684
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2020-3307
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to write arbitrary entries to the log file on the target device.

The vulnerability exists due to insufficient validation of user-supplied input in the web UI. A remote attacker can send a specially crafted HTTP request and send incorrect information to the system log on the affected system.


Affected software

Cisco Secure Firewall Management Center (formerly Firepower Management Center, FMC)

How to mitigate CVE-2020-3307

Install updates from vendor's website.

Cisco Secure Firewall Management Center (formerly Firepower Management Center, FMC) - update to 6.3.0.2

External References

Related Security Bulletins