Description
A vulnerability in the web-based management interface of Cisco Firepower Management Center could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack and perform arbitrary actions on an affected device. The vulnerability is due to insufficient CSRF protections for the web-based management interface of the affected device. An attacker could exploit this vulnerability by persuading a user of the interface to follow a malicious link. A successful exploit could allow the attacker to perform arbitrary actions on the targeted device via a web browser and with the privileges of the user. Cisco Bug IDs: CSCvb19750.
Published: 2018-06-21
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

No analysis available yet.

Remediation

No remediation available yet.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2018-1188 A vulnerability in the web-based management interface of Cisco Firepower Management Center could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack and perform arbitrary actions on an affected device. The vulnerability is due to insufficient CSRF protections for the web-based management interface of the affected device. An attacker could exploit this vulnerability by persuading a user of the interface to follow a malicious link. A successful exploit could allow the attacker to perform arbitrary actions on the targeted device via a web browser and with the privileges of the user. Cisco Bug IDs: CSCvb19750.
History

Fri, 29 Nov 2024 15:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 26 Nov 2024 16:45:00 +0000

Type Values Removed Values Added
First Time appeared Cisco secure Firewall Management Center
CPEs cpe:2.3:a:cisco:firepower_management_center:6.0.1:*:*:*:*:*:*:*
cpe:2.3:a:cisco:firepower_management_center:6.1.0:*:*:*:*:*:*:*
cpe:2.3:a:cisco:firepower_management_center:6.2.0:*:*:*:*:*:*:*
cpe:2.3:a:cisco:firepower_management_center:6.2.1:*:*:*:*:*:*:*
cpe:2.3:a:cisco:firepower_management_center:6.2.2:*:*:*:*:*:*:*
cpe:2.3:a:cisco:firepower_management_center:6.2.3:*:*:*:*:*:*:*
cpe:2.3:a:cisco:secure_firewall_management_center:6.0.1:*:*:*:*:*:*:*
cpe:2.3:a:cisco:secure_firewall_management_center:6.1.0:*:*:*:*:*:*:*
cpe:2.3:a:cisco:secure_firewall_management_center:6.2.0:*:*:*:*:*:*:*
cpe:2.3:a:cisco:secure_firewall_management_center:6.2.1:*:*:*:*:*:*:*
cpe:2.3:a:cisco:secure_firewall_management_center:6.2.2:*:*:*:*:*:*:*
cpe:2.3:a:cisco:secure_firewall_management_center:6.2.3:*:*:*:*:*:*:*
Vendors & Products Cisco firepower Management Center
Cisco secure Firewall Management Center

Subscriptions

Cisco Amp 7150 Amp 7150 Firmware Amp 8150 Amp 8150 Firmware Firepower Appliance 7010 Firepower Appliance 7010 Firmware Firepower Appliance 7020 Firepower Appliance 7020 Firmware Firepower Appliance 7030 Firepower Appliance 7030 Firmware Firepower Appliance 7050 Firepower Appliance 7050 Firmware Firepower Appliance 7110 Firepower Appliance 7110 Firmware Firepower Appliance 7115 Firepower Appliance 7115 Firmware Firepower Appliance 7120 Firepower Appliance 7120 Firmware Firepower Appliance 7125 Firepower Appliance 7125 Firmware Firepower Appliance 8120 Firepower Appliance 8120 Firmware Firepower Appliance 8130 Firepower Appliance 8130 Firmware Firepower Appliance 8140 Firepower Appliance 8140 Firmware Firepower Appliance 8250 Firepower Appliance 8250 Firmware Firepower Appliance 8260 Firepower Appliance 8260 Firmware Firepower Appliance 8270 Firepower Appliance 8270 Firmware Firepower Appliance 8290 Firepower Appliance 8290 Firmware Firepower Appliance 8350 Firepower Appliance 8350 Firmware Firepower Appliance 8360 Firepower Appliance 8360 Firmware Firepower Appliance 8370 Firepower Appliance 8370 Firmware Firepower Appliance 8390 Firepower Appliance 8390 Firmware Firepower Management Center 1000 Firepower Management Center 1000 Firmware Firepower Management Center 2000 Firepower Management Center 2000 Firmware Firepower Management Center 2500 Firepower Management Center 2500 Firmware Firepower Management Center 4000 Firepower Management Center 4000 Firmware Firepower Management Center 4500 Firepower Management Center 4500 Firmware Firepower Management Center Virtual Appliance Firesight Management Center 1500 Firesight Management Center 1500 Firmware Firesight Management Center 3500 Firesight Management Center 3500 Firmware Firesight Management Center 750 Firesight Management Center 750 Firmware Ngips Virtual Appliance Secure Firewall Management Center
cve-icon MITRE

Status: PUBLISHED

Assigner: cisco

Published:

Updated: 2024-11-29T14:55:53.272Z

Reserved: 2017-11-27T00:00:00.000Z

Link: CVE-2018-0365

cve-icon Vulnrichment

Updated: 2024-08-05T03:21:15.493Z

cve-icon NVD

Status : Modified

Published: 2018-06-21T11:29:01.133

Modified: 2024-11-26T16:09:02.407

Link: CVE-2018-0365

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses