A vulnerability in the web-based management interface of Cisco FMC Software could allow an authenticated, remote attacker to store malicious content for use in XSS attacks. This vulnerability is due to improper input sanitization in the web-based management interface of Cisco FMC Software. An attacker could exploit this vulnerability by persuading a user to click a malicious link. A successful exploit could allow the attacker to conduct a stored XSS attack on an affected device.
History

Tue, 05 Nov 2024 16:30:00 +0000

Type Values Removed Values Added
First Time appeared Cisco
Cisco firepower Management Center
CPEs cpe:2.3:a:cisco:firepower_management_center:6.2.3.17:*:*:*:*:*:*:*
cpe:2.3:a:cisco:firepower_management_center:6.2.3.18:*:*:*:*:*:*:*
cpe:2.3:a:cisco:firepower_management_center:6.4.0.13:*:*:*:*:*:*:*
cpe:2.3:a:cisco:firepower_management_center:6.4.0.14:*:*:*:*:*:*:*
cpe:2.3:a:cisco:firepower_management_center:6.4.0.15:*:*:*:*:*:*:*
cpe:2.3:a:cisco:firepower_management_center:6.4.0.16:*:*:*:*:*:*:*
cpe:2.3:a:cisco:firepower_management_center:6.4.0.17:*:*:*:*:*:*:*
cpe:2.3:a:cisco:firepower_management_center:6.4.0.18:*:*:*:*:*:*:*
cpe:2.3:a:cisco:firepower_management_center:6.6.0.1:*:*:*:*:*:*:*
cpe:2.3:a:cisco:firepower_management_center:6.6.0:*:*:*:*:*:*:*
cpe:2.3:a:cisco:firepower_management_center:6.6.1:*:*:*:*:*:*:*
cpe:2.3:a:cisco:firepower_management_center:6.6.3:*:*:*:*:*:*:*
cpe:2.3:a:cisco:firepower_management_center:6.6.4:*:*:*:*:*:*:*
cpe:2.3:a:cisco:firepower_management_center:6.6.5.1:*:*:*:*:*:*:*
cpe:2.3:a:cisco:firepower_management_center:6.6.5.2:*:*:*:*:*:*:*
cpe:2.3:a:cisco:firepower_management_center:6.6.5:*:*:*:*:*:*:*
cpe:2.3:a:cisco:firepower_management_center:6.6.7.1:*:*:*:*:*:*:*
cpe:2.3:a:cisco:firepower_management_center:6.6.7.2:*:*:*:*:*:*:*
cpe:2.3:a:cisco:firepower_management_center:6.6.7:*:*:*:*:*:*:*
cpe:2.3:a:cisco:firepower_management_center:7.0.6.1:*:*:*:*:*:*:*
cpe:2.3:a:cisco:firepower_management_center:7.0.6.2:*:*:*:*:*:*:*
cpe:2.3:a:cisco:firepower_management_center:7.0.6:*:*:*:*:*:*:*
cpe:2.3:a:cisco:firepower_management_center:7.2.4.1:*:*:*:*:*:*:*
cpe:2.3:a:cisco:firepower_management_center:7.2.4:*:*:*:*:*:*:*
cpe:2.3:a:cisco:firepower_management_center:7.2.5.1:*:*:*:*:*:*:*
cpe:2.3:a:cisco:firepower_management_center:7.2.5.2:*:*:*:*:*:*:*
cpe:2.3:a:cisco:firepower_management_center:7.2.5:*:*:*:*:*:*:*
cpe:2.3:a:cisco:firepower_management_center:7.2.6:*:*:*:*:*:*:*
cpe:2.3:a:cisco:firepower_management_center:7.2.7:*:*:*:*:*:*:*
cpe:2.3:a:cisco:firepower_management_center:7.2.8.1:*:*:*:*:*:*:*
cpe:2.3:a:cisco:firepower_management_center:7.2.8:*:*:*:*:*:*:*
cpe:2.3:a:cisco:firepower_management_center:7.3.0:*:*:*:*:*:*:*
cpe:2.3:a:cisco:firepower_management_center:7.3.1.1:*:*:*:*:*:*:*
cpe:2.3:a:cisco:firepower_management_center:7.3.1.2:*:*:*:*:*:*:*
cpe:2.3:a:cisco:firepower_management_center:7.3.1:*:*:*:*:*:*:*
cpe:2.3:a:cisco:firepower_management_center:7.4.0:*:*:*:*:*:*:*
cpe:2.3:a:cisco:firepower_management_center:7.4.1.1:*:*:*:*:*:*:*
cpe:2.3:a:cisco:firepower_management_center:7.4.1:*:*:*:*:*:*:*
Vendors & Products Cisco
Cisco firepower Management Center

Thu, 24 Oct 2024 17:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 23 Oct 2024 17:45:00 +0000

Type Values Removed Values Added
Description A vulnerability in the web-based management interface of Cisco FMC Software could allow an authenticated, remote attacker to store malicious content for use in XSS attacks. This vulnerability is due to improper input sanitization in the web-based management interface of Cisco FMC Software. An attacker could exploit this vulnerability by persuading a user to click a malicious link. A successful exploit could allow the attacker to conduct a stored XSS attack on an affected device.
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: cisco

Published: 2024-10-23T17:34:18.768Z

Updated: 2024-10-24T17:01:38.658Z

Reserved: 2023-11-08T15:08:07.658Z

Link: CVE-2024-20387

cve-icon Vulnrichment

Updated: 2024-10-24T17:01:34.296Z

cve-icon NVD

Status : Analyzed

Published: 2024-10-23T18:15:07.480

Modified: 2024-11-05T16:00:54.777

Link: CVE-2024-20387

cve-icon Redhat

No data.