A vulnerability in the web-based management interface of Cisco Firepower Management Center could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack and perform arbitrary actions on an affected device. The vulnerability is due to insufficient CSRF protections for the web-based management interface of the affected device. An attacker could exploit this vulnerability by persuading a user of the interface to follow a malicious link. A successful exploit could allow the attacker to perform arbitrary actions on the targeted device via a web browser and with the privileges of the user. Cisco Bug IDs: CSCvb19750.
Project Subscriptions
| Vendors | Products |
|---|---|
|
Cisco
Subscribe
|
Amp 7150
Subscribe
Amp 7150 Firmware
Subscribe
Amp 8150
Subscribe
Amp 8150 Firmware
Subscribe
Firepower Appliance 7010
Subscribe
Firepower Appliance 7010 Firmware
Subscribe
Firepower Appliance 7020
Subscribe
Firepower Appliance 7020 Firmware
Subscribe
Firepower Appliance 7030
Subscribe
Firepower Appliance 7030 Firmware
Subscribe
Firepower Appliance 7050
Subscribe
Firepower Appliance 7050 Firmware
Subscribe
Firepower Appliance 7110
Subscribe
Firepower Appliance 7110 Firmware
Subscribe
Firepower Appliance 7115
Subscribe
Firepower Appliance 7115 Firmware
Subscribe
Firepower Appliance 7120
Subscribe
Firepower Appliance 7120 Firmware
Subscribe
Firepower Appliance 7125
Subscribe
Firepower Appliance 7125 Firmware
Subscribe
Firepower Appliance 8120
Subscribe
Firepower Appliance 8120 Firmware
Subscribe
Firepower Appliance 8130
Subscribe
Firepower Appliance 8130 Firmware
Subscribe
Firepower Appliance 8140
Subscribe
Firepower Appliance 8140 Firmware
Subscribe
Firepower Appliance 8250
Subscribe
Firepower Appliance 8250 Firmware
Subscribe
Firepower Appliance 8260
Subscribe
Firepower Appliance 8260 Firmware
Subscribe
Firepower Appliance 8270
Subscribe
Firepower Appliance 8270 Firmware
Subscribe
Firepower Appliance 8290
Subscribe
Firepower Appliance 8290 Firmware
Subscribe
Firepower Appliance 8350
Subscribe
Firepower Appliance 8350 Firmware
Subscribe
Firepower Appliance 8360
Subscribe
Firepower Appliance 8360 Firmware
Subscribe
Firepower Appliance 8370
Subscribe
Firepower Appliance 8370 Firmware
Subscribe
Firepower Appliance 8390
Subscribe
Firepower Appliance 8390 Firmware
Subscribe
Firepower Management Center 1000
Subscribe
Firepower Management Center 1000 Firmware
Subscribe
Firepower Management Center 2000
Subscribe
Firepower Management Center 2000 Firmware
Subscribe
Firepower Management Center 2500
Subscribe
Firepower Management Center 2500 Firmware
Subscribe
Firepower Management Center 4000
Subscribe
Firepower Management Center 4000 Firmware
Subscribe
Firepower Management Center 4500
Subscribe
Firepower Management Center 4500 Firmware
Subscribe
Firepower Management Center Virtual Appliance
Subscribe
Firesight Management Center 1500
Subscribe
Firesight Management Center 1500 Firmware
Subscribe
Firesight Management Center 3500
Subscribe
Firesight Management Center 3500 Firmware
Subscribe
Firesight Management Center 750
Subscribe
Firesight Management Center 750 Firmware
Subscribe
Ngips Virtual Appliance
Subscribe
Secure Firewall Management Center
Subscribe
|
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2018-1188 | A vulnerability in the web-based management interface of Cisco Firepower Management Center could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack and perform arbitrary actions on an affected device. The vulnerability is due to insufficient CSRF protections for the web-based management interface of the affected device. An attacker could exploit this vulnerability by persuading a user of the interface to follow a malicious link. A successful exploit could allow the attacker to perform arbitrary actions on the targeted device via a web browser and with the privileges of the user. Cisco Bug IDs: CSCvb19750. |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Fri, 29 Nov 2024 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 26 Nov 2024 16:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Cisco secure Firewall Management Center
|
|
| CPEs | cpe:2.3:a:cisco:firepower_management_center:6.1.0:*:*:*:*:*:*:* cpe:2.3:a:cisco:firepower_management_center:6.2.0:*:*:*:*:*:*:* cpe:2.3:a:cisco:firepower_management_center:6.2.1:*:*:*:*:*:*:* cpe:2.3:a:cisco:firepower_management_center:6.2.2:*:*:*:*:*:*:* cpe:2.3:a:cisco:firepower_management_center:6.2.3:*:*:*:*:*:*:* |
cpe:2.3:a:cisco:secure_firewall_management_center:6.0.1:*:*:*:*:*:*:* cpe:2.3:a:cisco:secure_firewall_management_center:6.1.0:*:*:*:*:*:*:* cpe:2.3:a:cisco:secure_firewall_management_center:6.2.0:*:*:*:*:*:*:* cpe:2.3:a:cisco:secure_firewall_management_center:6.2.1:*:*:*:*:*:*:* cpe:2.3:a:cisco:secure_firewall_management_center:6.2.2:*:*:*:*:*:*:* cpe:2.3:a:cisco:secure_firewall_management_center:6.2.3:*:*:*:*:*:*:* |
| Vendors & Products |
Cisco firepower Management Center
|
Cisco secure Firewall Management Center
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: cisco
Published:
Updated: 2024-11-29T14:55:53.272Z
Reserved: 2017-11-27T00:00:00
Link: CVE-2018-0365
Updated: 2024-08-05T03:21:15.493Z
Status : Modified
Published: 2018-06-21T11:29:01.133
Modified: 2024-11-26T16:09:02.407
Link: CVE-2018-0365
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD