Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-g4hg-xr8w-wm8x

Опубликовано: 04 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 6.5

Описание

A vulnerability in the input protection mechanisms of Cisco Firepower Management Center (FMC) Software could allow an authenticated, remote attacker to view data without proper authorization. This vulnerability exists because of a protection mechanism that relies on the existence or values of a specific input. An attacker could exploit this vulnerability by modifying this input to bypass the protection mechanism and sending a crafted request to an affected device. A successful exploit could allow the attacker to view data beyond the scope of their authorization.

A vulnerability in the input protection mechanisms of Cisco Firepower Management Center (FMC) Software could allow an authenticated, remote attacker to view data without proper authorization. This vulnerability exists because of a protection mechanism that relies on the existence or values of a specific input. An attacker could exploit this vulnerability by modifying this input to bypass the protection mechanism and sending a crafted request to an affected device. A successful exploit could allow the attacker to view data beyond the scope of their authorization.

EPSS

Процентиль: 40%
0.00184
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-20
CWE-807

Связанные уязвимости

CVSS3: 6.5
nvd
почти 4 года назад

A vulnerability in the input protection mechanisms of Cisco Firepower Management Center (FMC) Software could allow an authenticated, remote attacker to view data without proper authorization. This vulnerability exists because of a protection mechanism that relies on the existence or values of a specific input. An attacker could exploit this vulnerability by modifying this input to bypass the protection mechanism and sending a crafted request to an affected device. A successful exploit could allow the attacker to view data beyond the scope of their authorization.

CVSS3: 4.3
fstec
почти 4 года назад

Уязвимость механизма защиты ввода программного обеспечения администрирования сети Cisco Firepower Management Center (FMC), позволяющая нарушителю раскрыть защищаемую информацию

EPSS

Процентиль: 40%
0.00184
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-20
CWE-807