Improper access control in Cisco Secure Firewall Management Center (formerly Firepower Management Center, FMC) - CVE-2021-1477
Published: April 29, 2021
Vulnerability identifier: #VU52733
CSH Severity: Low
CVSS v4: 5.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2021-1477
CWE-ID: CWE-284
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to gain unauthorized access to otherwise restricted functionality.
The vulnerability exists due to improper access restrictions. A remote authenticated attacker can overwrite policies and impact the configuration and operation of the affected device.
Affected software
Cisco Secure Firewall Management Center (formerly Firepower Management Center, FMC)
How to mitigate CVE-2021-1477
Install updates from vendor's website.
Cisco Secure Firewall Management Center (formerly Firepower Management Center, FMC) - addressed in versions 6.6.3, 6.7.0.2