Improper access control in Cisco Secure Firewall Management Center (formerly Firepower Management Center, FMC) - CVE-2021-1477

 

Improper access control in Cisco Secure Firewall Management Center (formerly Firepower Management Center, FMC) - CVE-2021-1477

Published: April 29, 2021


Vulnerability identifier: #VU52733
CSH Severity: Low
CVSS v4: 5.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2021-1477
CWE-ID: CWE-284
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to gain unauthorized access to otherwise restricted functionality.

The vulnerability exists due to improper access restrictions. A remote authenticated attacker can overwrite policies and impact the configuration and operation of the affected device.


Affected software

Cisco Secure Firewall Management Center (formerly Firepower Management Center, FMC)

How to mitigate CVE-2021-1477

Install updates from vendor's website.

Cisco Secure Firewall Management Center (formerly Firepower Management Center, FMC) - addressed in versions 6.6.3, 6.7.0.2

External References

Related Security Bulletins