Description
Multiple vulnerabilities in the web-based management interface of Cisco Firepower Management Center (FMC) could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web-based management interface. These vulnerabilities are due to insufficient validation of user-supplied input by the web-based management interface. An attacker could exploit these vulnerabilities by persuading a user of the interface to click a crafted link. A successful exploit could allow the attacker to execute arbitrary script code in the context of the interface or access sensitive, browser-based information.
Published: 2019-10-16
Score: 4.8 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

No analysis available yet.

Remediation

No remediation available yet.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2019-6276 Multiple vulnerabilities in the web-based management interface of Cisco Firepower Management Center (FMC) could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web-based management interface. These vulnerabilities are due to insufficient validation of user-supplied input by the web-based management interface. An attacker could exploit these vulnerabilities by persuading a user of the interface to click a crafted link. A successful exploit could allow the attacker to execute arbitrary script code in the context of the interface or access sensitive, browser-based information.
History

Thu, 21 Nov 2024 19:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Subscriptions

Cisco Amp 7150 Amp 7150 Firmware Amp 8150 Amp 8150 Firmware Firepower Appliance 7010 Firepower Appliance 7010 Firmware Firepower Appliance 7020 Firepower Appliance 7020 Firmware Firepower Appliance 7030 Firepower Appliance 7030 Firmware Firepower Appliance 7050 Firepower Appliance 7050 Firmware Firepower Appliance 7110 Firepower Appliance 7110 Firmware Firepower Appliance 7115 Firepower Appliance 7115 Firmware Firepower Appliance 7120 Firepower Appliance 7120 Firmware Firepower Appliance 7125 Firepower Appliance 7125 Firmware Firepower Appliance 8120 Firepower Appliance 8120 Firmware Firepower Appliance 8130 Firepower Appliance 8130 Firmware Firepower Appliance 8140 Firepower Appliance 8140 Firmware Firepower Appliance 8250 Firepower Appliance 8250 Firmware Firepower Appliance 8260 Firepower Appliance 8260 Firmware Firepower Appliance 8270 Firepower Appliance 8270 Firmware Firepower Appliance 8290 Firepower Appliance 8290 Firmware Firepower Appliance 8350 Firepower Appliance 8350 Firmware Firepower Appliance 8360 Firepower Appliance 8360 Firmware Firepower Appliance 8370 Firepower Appliance 8370 Firmware Firepower Appliance 8390 Firepower Appliance 8390 Firmware Firepower Management Center 1000 Firepower Management Center 1000 Firmware Firepower Management Center 1600 Firepower Management Center 1600 Firmware Firepower Management Center 2000 Firepower Management Center 2000 Firmware Firepower Management Center 2500 Firepower Management Center 2500 Firmware Firepower Management Center 2600 Firepower Management Center 2600 Firmware Firepower Management Center 4000 Firepower Management Center 4000 Firmware Firepower Management Center 4500 Firepower Management Center 4500 Firmware Firepower Management Center 4600 Firepower Management Center 4600 Firmware Firepower Management Center Virtual Appliance Firepower Management Center Virtual Appliance Firmware Firesight Management Center 1500 Firesight Management Center 1500 Firmware Firesight Management Center 3500 Firesight Management Center 3500 Firmware Firesight Management Center 750 Firesight Management Center 750 Firmware Ngips Virtual Appliance Ngips Virtual Appliance Firmware
cve-icon MITRE

Status: PUBLISHED

Assigner: cisco

Published:

Updated: 2024-11-21T19:07:35.426Z

Reserved: 2019-08-20T00:00:00.000Z

Link: CVE-2019-15268

cve-icon Vulnrichment

Updated: 2024-08-05T00:42:03.631Z

cve-icon NVD

Status : Modified

Published: 2019-10-16T19:15:14.347

Modified: 2024-11-21T04:28:19.720

Link: CVE-2019-15268

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses