MEDIUM✓ PATCH🇵🇱 Wersja polska

CVE-2022-20941

CVSS 5.3v3.1pub. 2022-11-15upd. 2024-11-26

A vulnerability in the web-based management interface of Cisco Firepower Management Center (FMC) Software could allow an unauthenticated, remote attacker to access sensitive information. This vulnerability is due to missing authorization for certain resources in the web-based management interface together with insufficient entropy in these resource names. An attacker could exploit this vulnerability by sending a series of HTTPS requests to an affected device to enumerate resources on the device. A successful exploit could allow the attacker to retrieve sensitive information from the device.

CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
  • Cisco Secure Firewall Management Center

    APP
    Cisco
    6.1.06.1.0.16.1.0.26.1.0.36.1.0.46.1.0.56.1.0.66.1.0.76.2.06.2.0.16.2.0.26.2.0.36.2.0.46.2.0.56.2.0.6+ 78 more
🟢
PATCH AVAILABLE
Vendor update available. Deploy in standard maintenance cycle.
CWE
References

Related vulnerabilities

CVE-2026-20131CRITICAL10.0⚠ KEVPL ✓same product

RCE przez insecure deserialization w Cisco Secure Firewall Management Center

CVE-2025-20265CRITICAL10.0PL ✓same product

RCE przez RADIUS w Cisco Secure Firewall Management Center

CVE-2024-20424CRITICAL9.9PL ✓same product

Command injection w Cisco Secure Firewall Management Center — RCE jako root

CVE-2023-20048CRITICAL9.9PL ✓same product

Cisco FMC: nieautoryzowane wykonanie komend konfiguracyjnych na urządzeniach FTD

CVE-2019-16028CRITICAL9.8PL ✓same product

Cisco FMC: pominięcie uwierzytelnienia przez błędną obsługę LDAP