#VU21627 Path traversal in Cisco Secure Firewall Management Center (formerly Firepower Management Center, FMC) - CVE-2019-12691
Published: October 8, 2019
Cisco Secure Firewall Management Center (formerly Firepower Management Center, FMC)
Cisco Systems, Inc
Description
The vulnerability allows a remote attacker to perform directory traversal attacks.
The vulnerability exists due to input validation error by the web-based management interface when processing directory traversal sequences. A remote authenticated attacker can send a specially crafted HTTP request to the web-based management interface, bypass security restrictions and gain access to the underlying filesystem of the affected device.