CVE-2023-20005

CVSS 3.1 Score 6.1 of 10 (medium)

Details

Published Nov 1, 2023
Updated: Jan 25, 2024
CWE ID 79

Summary

CVE-2023-20005 refers to multiple vulnerabilities found in the web-based management interface of Cisco Firepower Management Center (FMC) Software. These vulnerabilities enable an unauthenticated, remote attacker to execute stored cross-site scripting (XSS) attacks against users of the interface on affected devices. The root cause is insufficient input validation by the web interface. An attacker can exploit these flaws by inserting malicious data into various input fields. Successful exploitation allows the attacker to execute arbitrary script code in the context of the interface or access sensitive browser-based information. In some instances, the vulnerabilities may also cause temporary availability impacts to portions of the FMC Dashboard.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share

Affected Products

  • Cisco FirePOWER Management Center

Affected Vendors

  • Cisco Systems Inc