Vulnerabilities > Cisco > Secure Firewall Management Center > 6.4.0.16

DATE CVE VULNERABILITY TITLE RISK
2023-11-01 CVE-2023-20114 Improper Input Validation vulnerability in Cisco Secure Firewall Management Center
A vulnerability in the file download feature of Cisco Firepower Management Center (FMC) Software could allow an authenticated, remote attacker to download arbitrary files from an affected system.
network
low complexity
cisco CWE-20
6.5
2023-11-01 CVE-2023-20155 Resource Exhaustion vulnerability in Cisco Secure Firewall Management Center
A vulnerability in a logging API in Cisco Firepower Management Center (FMC) Software could allow an unauthenticated, remote attacker to cause the device to become unresponsive or trigger an unexpected reload.
network
low complexity
cisco CWE-400
6.5
2022-05-03 CVE-2022-20740 Cross-site Scripting vulnerability in Cisco Secure Firewall Management Center
A vulnerability in the web-based management interface of Cisco Firepower Management Center (FMC) Software could allow an unauthenticated, remote attacker to conduct a cross-site scripting attack.
network
low complexity
cisco CWE-79
6.1
2022-05-03 CVE-2022-20744 Unspecified vulnerability in Cisco Secure Firewall Management Center
A vulnerability in the input protection mechanisms of Cisco Firepower Management Center (FMC) Software could allow an authenticated, remote attacker to view data without proper authorization.
network
low complexity
cisco
6.5
2021-01-13 CVE-2021-1267 XML Entity Expansion vulnerability in Cisco Secure Firewall Management Center
A vulnerability in the dashboard widget of Cisco Firepower Management Center (FMC) Software could allow an authenticated, remote attacker to cause a denial of service (DoS) condition on an affected device.
network
low complexity
cisco CWE-776
4.3
2021-01-13 CVE-2021-1239 Cross-site Scripting vulnerability in Cisco Secure Firewall Management Center
Multiple vulnerabilities in the web-based management interface of Cisco Firepower Management Center (FMC) could allow an authenticated, remote attacker to conduct a stored cross-site scripting (XSS) attack against a user of the interface of an affected system.
network
low complexity
cisco CWE-79
4.8
2021-01-13 CVE-2021-1238 Cross-site Scripting vulnerability in Cisco Secure Firewall Management Center
Multiple vulnerabilities in the web-based management interface of Cisco Firepower Management Center (FMC) could allow an authenticated, remote attacker to conduct a stored cross-site scripting (XSS) attack against a user of the interface of an affected system.
network
low complexity
cisco CWE-79
4.8
2021-01-13 CVE-2021-1126 Incorrect Permission Assignment for Critical Resource vulnerability in Cisco Secure Firewall Management Center
A vulnerability in the storage of proxy server credentials of Cisco Firepower Management Center (FMC) could allow an authenticated, local attacker to view credentials for a configured proxy server.
local
low complexity
cisco CWE-732
5.5
2020-10-21 CVE-2020-3557 Improper Certificate Validation vulnerability in Cisco Secure Firewall Management Center
A vulnerability in the host input API daemon of Cisco Firepower Management Center (FMC) Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device.
network
low complexity
cisco CWE-295
5.3
2020-10-21 CVE-2020-3553 Cross-site Scripting vulnerability in Cisco Secure Firewall Management Center
Multiple vulnerabilities in the web-based management interface of Cisco Firepower Management Center (FMC) Software could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface.
network
low complexity
cisco CWE-79
6.1