#VU99313 Improper privilege management in Cisco Secure Firewall Management Center (formerly Firepower Management Center, FMC) - CVE-2024-20374
Published: October 24, 2024
Cisco Secure Firewall Management Center (formerly Firepower Management Center, FMC)
Cisco Systems, Inc
Description
The vulnerability allows a remote user to execute arbitrary commands.
The vulnerability exists due to insufficient input validation of certain HTTP request parameters that are sent to the web-based management interface. A remote administrator can send a specially crafted HTTP request and execute commands as the root user on the target device.