Reliance on Untrusted Inputs in a Security Decision in Cisco Secure Firewall Management Center (formerly Firepower Management Center, FMC) - CVE-2022-20744

 

Reliance on Untrusted Inputs in a Security Decision in Cisco Secure Firewall Management Center (formerly Firepower Management Center, FMC) - CVE-2022-20744

Published: April 28, 2022


Vulnerability identifier: #VU62680
CSH Severity: Low
CVSS v4: 5.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2022-20744
CWE-ID: CWE-807
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to gain access to potentially sensitive information.

The vulnerability exists due to a protection mechanism that relies on the existence or values of a specific input. A remote user can modify this input to bypass the protection mechanism and gain unauthorized access to sensitive information on the system.


Affected software

Cisco Secure Firewall Management Center (formerly Firepower Management Center, FMC)

How to mitigate CVE-2022-20744

Install updates from vendor's website.

Cisco Secure Firewall Management Center (formerly Firepower Management Center, FMC) - update to 7.1

External References

Related Security Bulletins