Cisco Firepower Management Center(FMC)是美国思科(Cisco)公司的新一代防火墙管理中心软件。 Cisco Firepower Management Center: 6.4.0.11 存在跨站脚本漏洞,该漏洞源于在基于Web的管理界面中未对用户提供的数据进行充分的清理而造成的。经过身份验证的远程攻击者可以诱骗受害者遵循特制链接,并在易受攻击的网站的上下文中在用户浏览器中执行任意HTML和脚本代码。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Cisco | Cisco Firepower Management Center | n/a | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2021-1445 | 8.6 HIGH | Cisco Adaptive Security Appliance Software and Firepower Threat Defense Software Web Servi |
| CVE-2021-1501 | 8.6 HIGH | Cisco Adaptive Security Appliance Software and Cisco Firepower Threat Defense Software SIP |
| CVE-2021-1504 | 8.6 HIGH | Cisco Adaptive Security Appliance Software and Firepower Threat Defense Software Web Servi |
| CVE-2021-1493 | 8.5 HIGH | Cisco Adaptive Security Appliance Software and Firepower Threat Defense Software Web Servi |
| CVE-2021-1476 | 6.7 MEDIUM | Cisco Adaptive Security Appliance Software and Firepower Threat Defense Software Command I |
| CVE-2021-1488 | 6.7 MEDIUM | Cisco Adaptive Security Appliance Software and Firepower Threat Defense Software for Firep |
| CVE-2021-1256 | 6.0 MEDIUM | Cisco Firepower Threat Defense Software Command File Overwrite Vulnerability |
| CVE-2021-1495 | 5.8 MEDIUM | Multiple Cisco Products Snort HTTP Detection Engine File Policy Bypass Vulnerability |
| CVE-2021-1369 | 5.4 MEDIUM | Cisco Firepower Device Manager On-Box Software XML External Entity Vulnerability |
| CVE-2021-1456 | 4.8 MEDIUM | Cisco Firepower Management Center Software Cross-Site Scripting Vulnerabilities |
| CVE-2021-1457 | 4.8 MEDIUM | Cisco Firepower Management Center Software Cross-Site Scripting Vulnerabilities |
| CVE-2021-1458 | 4.8 MEDIUM | Cisco Firepower Management Center Software Cross-Site Scripting Vulnerabilities |
| CVE-2021-1477 | 4.3 MEDIUM | Cisco Firepower Management Center Software Policy Vulnerability |
| CVE-2021-1402 | Cisco Firepower Threat Defense Software SSL Decryption Policy Denial of Service Vulnerabil | |
| CVE-2021-1448 | Cisco Firepower Threat Defense Software Command Injection Vulnerability | |
| CVE-2021-1489 | Cisco Firepower Device Manager Software Filesystem Space Exhaustion Denial of Service Vuln |
No comments yet