Small Space of Random Values in Cisco Secure Firewall Management Center (formerly Firepower Management Center, FMC) - CVE-2022-20941
Published: November 11, 2022
Cisco Secure Firewall Management Center (formerly Firepower Management Center, FMC)
Cisco Systems, Inc
Description
The vulnerability allows a remote attacker to gain access to potentially sensitive information.
The vulnerability exists due to missing authorization for certain resources in the web-based management interface together with insufficient entropy in these resource names. A remote attacker can gain unauthorized access to sensitive information on the system.