#VU99292 OS Command Injection in Cisco Secure Firewall Management Center (formerly Firepower Management Center, FMC) - CVE-2024-20424
Published: October 24, 2024
Cisco Secure Firewall Management Center (formerly Firepower Management Center, FMC)
Cisco Systems, Inc
Description
The vulnerability allows a remote user to execute arbitrary shell commands on the target system.
The vulnerability exists due to improper input validation in the web-based management interface. A remote user with at least the role of Security Analyst (Read Only) can send a specially crafted HTTP request to the affected device and execute arbitrary OS commands on the target system with root privileges.