Vulnerabilities > Cisco > Secure Firewall Management Center > 6.0.0

DATE CVE VULNERABILITY TITLE RISK
2019-10-02 CVE-2019-12691 Path Traversal vulnerability in Cisco Secure Firewall Management Center
A vulnerability in the web-based management interface of Cisco Firepower Management Center (FMC) Software could allow an authenticated, remote attacker to perform a directory traversal attack on an affected device.
network
low complexity
cisco CWE-22
4.9
2019-10-02 CVE-2019-12690 OS Command Injection vulnerability in Cisco Secure Firewall Management Center
A vulnerability in the web UI of the Cisco Firepower Management Center (FMC) could allow an authenticated, remote attacker to inject arbitrary commands that are executed with the privileges of the root user of the underlying operating system.
network
low complexity
cisco CWE-78
7.2
2019-10-02 CVE-2019-12689 Improper Input Validation vulnerability in Cisco Secure Firewall Management Center
A vulnerability in the web-based management interface of Cisco Firepower Management Center (FMC) Software could allow an authenticated, remote attacker to execute arbitrary code on the underlying operating system of an affected device.
network
low complexity
cisco CWE-20
8.8
2019-10-02 CVE-2019-12683 SQL Injection vulnerability in Cisco Secure Firewall Management Center
Multiple vulnerabilities in the web-based management interface of Cisco Firepower Management Center (FMC) Software could allow an authenticated, remote attacker to execute arbitrary SQL injections on an affected device.
network
low complexity
cisco CWE-89
8.8
2019-10-02 CVE-2019-12681 SQL Injection vulnerability in Cisco Secure Firewall Management Center
Multiple vulnerabilities in the web-based management interface of Cisco Firepower Management Center (FMC) Software could allow an authenticated, remote attacker to execute arbitrary SQL injections on an affected device.
network
low complexity
cisco CWE-89
8.8
2019-05-03 CVE-2019-1699 OS Command Injection vulnerability in Cisco Secure Firewall Management Center
A vulnerability in the CLI of Cisco Firepower Threat Defense (FTD) Software could allow an authenticated, local attacker to perform a command injection attack.
local
low complexity
cisco CWE-78
7.8
2019-02-07 CVE-2019-1671 Cross-site Scripting vulnerability in Cisco Secure Firewall Management Center
A vulnerability in the web-based management interface of Cisco Firepower Management Center (FMC) could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web-based management interface of an affected system.
network
low complexity
cisco CWE-79
6.1
2018-07-16 CVE-2018-0385 Improper Input Validation vulnerability in Cisco Secure Firewall Management Center
A vulnerability in the detection engine parsing of Security Socket Layer (SSL) protocol packets for Cisco Firepower System Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition due to the Snort process unexpectedly restarting.
network
low complexity
cisco CWE-20
7.5
2018-07-16 CVE-2018-0384 Protection Mechanism Failure vulnerability in Cisco Secure Firewall Management Center
A vulnerability in the detection engine of Cisco FireSIGHT System Software could allow an unauthenticated, remote attacker to bypass a URL-based access control policy that is configured to block traffic for an affected system.
network
low complexity
cisco CWE-693
5.8
2018-04-19 CVE-2018-0233 Resource Exhaustion vulnerability in Cisco Secure Firewall Management Center
A vulnerability in the Secure Sockets Layer (SSL) packet reassembly functionality of the detection engine in Cisco Firepower System Software could allow an unauthenticated, remote attacker to cause the detection engine to consume excessive system memory on an affected device, which could cause a denial of service (DoS) condition.
network
low complexity
cisco CWE-400
8.6