A vulnerability in the web management interface of Cisco Firepower Management Center (FMC) Software could allow an authenticated, remote attacker to bypass security protections and upload malicious files to the affected system. This vulnerability is due to improper validation of files uploaded to the web management interface of Cisco FMC Software. An attacker could exploit this vulnerability by uploading a maliciously crafted file to a device running affected software. A successful exploit could allow the attacker to store malicious files on the device, which they could access later to conduct additional attacks, including executing arbitrary code on the affected device with root privileges.
History

Tue, 26 Nov 2024 16:45:00 +0000

Type Values Removed Values Added
First Time appeared Cisco secure Firewall Management Center
CPEs cpe:2.3:a:cisco:firepower_management_center:*:*:*:*:*:*:*:* cpe:2.3:a:cisco:secure_firewall_management_center:*:*:*:*:*:*:*:*
Vendors & Products Cisco firepower Management Center
Cisco secure Firewall Management Center

Wed, 06 Nov 2024 17:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


cve-icon MITRE

Status: PUBLISHED

Assigner: cisco

Published: 2022-05-03T03:15:56.090995Z

Updated: 2024-11-06T16:19:47.640Z

Reserved: 2021-11-02T00:00:00

Link: CVE-2022-20743

cve-icon Vulnrichment

Updated: 2024-08-03T02:24:49.416Z

cve-icon NVD

Status : Modified

Published: 2022-05-03T04:15:09.377

Modified: 2024-11-26T16:09:02.407

Link: CVE-2022-20743

cve-icon Redhat

No data.