Description
A vulnerability in the Cisco Firepower Chassis Manager (FCM) of Cisco FXOS Software could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack against a user of an affected device. The vulnerability is due to insufficient CSRF protections for the FCM interface. An attacker could exploit this vulnerability by persuading a targeted user to click a malicious link. A successful exploit could allow the attacker to send arbitrary requests that could take unauthorized actions on behalf of the targeted user.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2020-24727 | A vulnerability in the Cisco Firepower Chassis Manager (FCM) of Cisco FXOS Software could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack against a user of an affected device. The vulnerability is due to insufficient CSRF protections for the FCM interface. An attacker could exploit this vulnerability by persuading a targeted user to click a malicious link. A successful exploit could allow the attacker to send arbitrary requests that could take unauthorized actions on behalf of the targeted user. |
References
History
Wed, 13 Nov 2024 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Subscriptions
Cisco
Subscribe
Firepower 4110
Subscribe
Firepower 4112
Subscribe
Firepower 4115
Subscribe
Firepower 4120
Subscribe
Firepower 4125
Subscribe
Firepower 4140
Subscribe
Firepower 4145
Subscribe
Firepower 4150
Subscribe
Firepower 9300 Sm-24
Subscribe
Firepower 9300 Sm-36
Subscribe
Firepower 9300 Sm-40
Subscribe
Firepower 9300 Sm-44
Subscribe
Firepower 9300 Sm-44 X 3
Subscribe
Firepower 9300 Sm-48
Subscribe
Firepower 9300 Sm-56
Subscribe
Firepower 9300 Sm-56 X 3
Subscribe
Firepower Extensible Operating System
Subscribe
Status: PUBLISHED
Assigner: cisco
Published:
Updated: 2024-11-13T17:48:57.327Z
Reserved: 2019-12-12T00:00:00.000Z
Link: CVE-2020-3456
Updated: 2024-08-04T07:37:54.615Z
Status : Modified
Published: 2020-10-21T19:15:16.263
Modified: 2024-11-21T05:31:06.343
Link: CVE-2020-3456
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD