Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-3fhj-6hmf-3c6x

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 4.3

Описание

A vulnerability in an access control mechanism of Cisco Firepower Management Center (FMC) Software could allow an authenticated, remote attacker to access services beyond the scope of their authorization. This vulnerability is due to insufficient enforcement of access control in the affected software. An attacker could exploit this vulnerability by directly accessing the internal services of an affected device. A successful exploit could allow the attacker to overwrite policies and impact the configuration and operation of the affected device.

A vulnerability in an access control mechanism of Cisco Firepower Management Center (FMC) Software could allow an authenticated, remote attacker to access services beyond the scope of their authorization. This vulnerability is due to insufficient enforcement of access control in the affected software. An attacker could exploit this vulnerability by directly accessing the internal services of an affected device. A successful exploit could allow the attacker to overwrite policies and impact the configuration and operation of the affected device.

EPSS

Процентиль: 36%
0.00149
Низкий

4.3 Medium

CVSS3

Дефекты

CWE-269
CWE-284

Связанные уязвимости

CVSS3: 4.3
nvd
почти 5 лет назад

A vulnerability in an access control mechanism of Cisco Firepower Management Center (FMC) Software could allow an authenticated, remote attacker to access services beyond the scope of their authorization. This vulnerability is due to insufficient enforcement of access control in the affected software. An attacker could exploit this vulnerability by directly accessing the internal services of an affected device. A successful exploit could allow the attacker to overwrite policies and impact the configuration and operation of the affected device.

CVSS3: 4.3
fstec
почти 5 лет назад

Уязвимость механизма управления доступом программного обеспечения администрирования сети Cisco Firepower Management Center (FMC), позволяющая нарушителю получить доступ на изменение, добавление или удаление данных, получить несанкционированный доступ к защищаемой информации

EPSS

Процентиль: 36%
0.00149
Низкий

4.3 Medium

CVSS3

Дефекты

CWE-269
CWE-284