CVE-2024-20274
Cisco Secure Firewall Management Center HTML Injection Vulnerability
Description
A vulnerability in the web-based management interface of Cisco Secure Firewall Management Center (FMC) Software, formerly Firepower Management Center Software, could allow an authenticated, remote attacker to inject arbitrary HTML content into a device-generated document. This vulnerability is due to improper validation of user-supplied data. An attacker could exploit this vulnerability by submitting malicious content to an affected device and using the device to generate a document that contains sensitive information. A successful exploit could allow the attacker to alter the standard layout of the device-generated documents, access arbitrary files from the underlying operating system, and conduct server-side request forgery (SSRF) attacks. To successfully exploit this vulnerability, an attacker would need valid credentials for a user account with policy-editing permissions, such as Network Admin, Intrusion Admin, or any custom user role with the same capabilities.
Weakness: CWE-20
Affected products
| Vendor | Product | Category | Matched by |
|---|---|---|---|
| Cisco | Cisco Secure Firewall Management Center Check your version | Network & Security Management | cna-assigner |
Vendor-reported products (1)
- Cisco · Cisco Firepower Management Center
Vendor advisory
cisco-sa-fmc-html-inj-nfJeYHxz
Cisco Secure Firewall Management Center Software HTML Injection Vulnerability
Cisco’s rating: Medium (advisory CVSS 5.5) · Published Oct 23, 2024
Bug IDs: CSCwe20634 , CSCwe20641 , CSCwh41922 , CSCwh41958 , CSCwi26709 , CSCwi93842 , CSCwj72448
The vendor’s rating applies to the whole advisory and can differ from this CVE’s own CVSS severity. Where this comes from