Vulnerabilities > Cisco > Firepower Management Center

DATE CVE VULNERABILITY TITLE RISK
2017-10-05 CVE-2017-12245 Missing Release of Resource after Effective Lifetime vulnerability in Cisco Firepower Management Center
A vulnerability in SSL traffic decryption for Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause depletion of system memory, aka a Firepower Detection Engine SSL Decryption Memory Consumption Denial of Service vulnerability.
network
low complexity
cisco CWE-772
8.6
2017-10-05 CVE-2017-12244 Improper Input Validation vulnerability in Cisco Firepower Management Center
A vulnerability in the detection engine parsing of IPv6 packets for Cisco Firepower System Software could allow an unauthenticated, remote attacker to cause high CPU utilization or to cause a denial of service (DoS) condition because the Snort process restarts unexpectedly.
network
low complexity
cisco CWE-20
8.6
2017-09-07 CVE-2017-12221 Cross-site Scripting vulnerability in Cisco Firepower Management Center
A vulnerability in the web framework of Cisco Firepower Management Center could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web interface of the affected software.
network
low complexity
cisco CWE-79
5.4
2017-09-07 CVE-2017-12220 Cross-site Scripting vulnerability in Cisco Firepower Management Center
A vulnerability in the web-based management interface of Cisco Firepower Management Center could allow an unauthenticated, remote attacker to conduct a reflected cross-site scripting (XSS) attack against a user of the web-based management interface of an affected device.
network
low complexity
cisco CWE-79
6.1
2017-07-04 CVE-2017-6717 Cross-site Scripting vulnerability in Cisco Firepower Management Center
A vulnerability in the web framework of Cisco Firepower Management Center could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web interface.
network
low complexity
cisco CWE-79
5.4
2017-07-04 CVE-2017-6716 Cross-site Scripting vulnerability in Cisco Firepower Management Center
A vulnerability in the web framework code of Cisco Firepower Management Center could allow an authenticated, remote attacker to conduct a stored cross-site scripting (XSS) attack against a user of the web interface of an affected system.
network
low complexity
cisco CWE-79
5.4
2017-07-04 CVE-2017-6715 Cross-site Scripting vulnerability in Cisco Firepower Management Center
A vulnerability in the web framework of Cisco Firepower Management Center could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web interface.
network
low complexity
cisco CWE-79
5.4
2017-06-13 CVE-2017-6673 Information Exposure vulnerability in Cisco Firepower Management Center 6.1.0.2/6.2.0
A vulnerability in Cisco Firepower Management Center could allow an authenticated, remote attacker to obtain user information.
network
low complexity
cisco CWE-200
6.5
2017-04-20 CVE-2016-6368 Resource Management Errors vulnerability in Cisco Firepower Management Center
A vulnerability in the detection engine parsing of Pragmatic General Multicast (PGM) protocol packets for Cisco Firepower System Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition due to the Snort process unexpectedly restarting.
network
low complexity
cisco CWE-399
8.6
2017-04-07 CVE-2017-3885 Resource Exhaustion vulnerability in Cisco Firepower Management Center
A vulnerability in the detection engine reassembly of Secure Sockets Layer (SSL) packets for Cisco Firepower System Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition because the Snort process consumes a high level of CPU resources.
network
high complexity
cisco CWE-400
5.9