A vulnerability in the web-based management interface of Cisco FMC Software could allow an authenticated, remote attacker to store malicious content for use in XSS attacks. This vulnerability is due to improper input sanitization in the web-based management interface of Cisco FMC Software. An attacker could exploit this vulnerability by persuading a user to click a malicious link. A successful exploit could allow the attacker to conduct a stored XSS attack on an affected device.
References
Link | Resource |
---|---|
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-fmc-xss-infodisc-RL4mJFer | Vendor Advisory |
Configurations
Configuration 1 (hide)
|
History
05 Nov 2024, 16:00
Type | Values Removed | Values Added |
---|---|---|
First Time |
Cisco
Cisco firepower Management Center |
|
CPE | cpe:2.3:a:cisco:firepower_management_center:7.0.6.2:*:*:*:*:*:*:* cpe:2.3:a:cisco:firepower_management_center:6.6.4:*:*:*:*:*:*:* cpe:2.3:a:cisco:firepower_management_center:6.4.0.13:*:*:*:*:*:*:* cpe:2.3:a:cisco:firepower_management_center:7.3.1.1:*:*:*:*:*:*:* cpe:2.3:a:cisco:firepower_management_center:6.6.5:*:*:*:*:*:*:* cpe:2.3:a:cisco:firepower_management_center:6.6.3:*:*:*:*:*:*:* cpe:2.3:a:cisco:firepower_management_center:6.2.3.17:*:*:*:*:*:*:* cpe:2.3:a:cisco:firepower_management_center:6.6.0.1:*:*:*:*:*:*:* cpe:2.3:a:cisco:firepower_management_center:7.2.5:*:*:*:*:*:*:* cpe:2.3:a:cisco:firepower_management_center:7.4.1:*:*:*:*:*:*:* cpe:2.3:a:cisco:firepower_management_center:6.4.0.14:*:*:*:*:*:*:* cpe:2.3:a:cisco:firepower_management_center:7.3.1:*:*:*:*:*:*:* cpe:2.3:a:cisco:firepower_management_center:6.6.5.2:*:*:*:*:*:*:* cpe:2.3:a:cisco:firepower_management_center:7.2.5.2:*:*:*:*:*:*:* cpe:2.3:a:cisco:firepower_management_center:7.2.8:*:*:*:*:*:*:* cpe:2.3:a:cisco:firepower_management_center:7.3.1.2:*:*:*:*:*:*:* cpe:2.3:a:cisco:firepower_management_center:7.0.6.1:*:*:*:*:*:*:* cpe:2.3:a:cisco:firepower_management_center:6.4.0.18:*:*:*:*:*:*:* cpe:2.3:a:cisco:firepower_management_center:6.6.7.1:*:*:*:*:*:*:* cpe:2.3:a:cisco:firepower_management_center:7.2.5.1:*:*:*:*:*:*:* cpe:2.3:a:cisco:firepower_management_center:6.2.3.18:*:*:*:*:*:*:* cpe:2.3:a:cisco:firepower_management_center:6.6.5.1:*:*:*:*:*:*:* cpe:2.3:a:cisco:firepower_management_center:7.2.6:*:*:*:*:*:*:* cpe:2.3:a:cisco:firepower_management_center:7.0.6:*:*:*:*:*:*:* cpe:2.3:a:cisco:firepower_management_center:6.6.7:*:*:*:*:*:*:* cpe:2.3:a:cisco:firepower_management_center:6.6.1:*:*:*:*:*:*:* cpe:2.3:a:cisco:firepower_management_center:7.2.4.1:*:*:*:*:*:*:* cpe:2.3:a:cisco:firepower_management_center:7.3.0:*:*:*:*:*:*:* cpe:2.3:a:cisco:firepower_management_center:6.4.0.16:*:*:*:*:*:*:* cpe:2.3:a:cisco:firepower_management_center:7.2.4:*:*:*:*:*:*:* cpe:2.3:a:cisco:firepower_management_center:6.6.0:*:*:*:*:*:*:* cpe:2.3:a:cisco:firepower_management_center:6.4.0.15:*:*:*:*:*:*:* cpe:2.3:a:cisco:firepower_management_center:7.2.8.1:*:*:*:*:*:*:* cpe:2.3:a:cisco:firepower_management_center:6.6.7.2:*:*:*:*:*:*:* cpe:2.3:a:cisco:firepower_management_center:7.2.7:*:*:*:*:*:*:* cpe:2.3:a:cisco:firepower_management_center:7.4.1.1:*:*:*:*:*:*:* cpe:2.3:a:cisco:firepower_management_center:7.4.0:*:*:*:*:*:*:* cpe:2.3:a:cisco:firepower_management_center:6.4.0.17:*:*:*:*:*:*:* |
|
References | () https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-fmc-xss-infodisc-RL4mJFer - Vendor Advisory |
25 Oct 2024, 12:56
Type | Values Removed | Values Added |
---|---|---|
Summary |
|
23 Oct 2024, 18:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2024-10-23 18:15
Updated : 2024-11-05 16:00
NVD link : CVE-2024-20387
Mitre link : CVE-2024-20387
CVE.ORG link : CVE-2024-20387
JSON object : View
Products Affected
cisco
- firepower_management_center
CWE
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')