📦 Secure Firewall Management Center

by Cisco

🔍 What is Secure Firewall Management Center?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2025-20265

CRITICAL CVSS 10.0 Aug 14, 2025

This critical vulnerability in Cisco Secure Firewall Management Center allows unauthenticated remote attackers to execute arbitrary shell commands with high privileges by sending crafted input during ...

CVE-2024-20424

CRITICAL CVSS 9.9 Oct 23, 2024

This vulnerability allows authenticated attackers with at least Security Analyst (Read Only) privileges to execute arbitrary commands as root on Cisco Secure Firewall Management Center devices. It aff...

CVE-2023-20048

CRITICAL CVSS 9.9 Nov 1, 2023

This vulnerability allows authenticated remote attackers to execute unauthorized configuration commands on Firepower Threat Defense devices managed by Cisco Firepower Management Center. Attackers need...

CVE-2024-20360

HIGH CVSS 8.8 May 22, 2024

This SQL injection vulnerability in Cisco Firepower Management Center (FMC) allows authenticated attackers with at least Read Only credentials to execute arbitrary SQL queries. Successful exploitation...

CVE-2023-20219

HIGH CVSS 7.2 Nov 1, 2023

This vulnerability allows authenticated remote attackers with valid device credentials (no admin privileges required) to execute arbitrary commands on Cisco Firepower Management Center (FMC) systems. ...

CVE-2023-20155

HIGH CVSS 7.5 Nov 1, 2023

This vulnerability in Cisco Firepower Management Center allows unauthenticated attackers to cause denial of service by overwhelming a logging API, potentially crashing the device. It also enables auth...

CVE-2021-40116

HIGH CVSS 8.6 Oct 27, 2021

This vulnerability in Cisco products with Snort3 configured allows unauthenticated remote attackers to cause denial of service by sending crafted IP packets. The attack causes through traffic to be dr...

CVE-2025-20301

MEDIUM CVSS 6.5 Aug 14, 2025

This vulnerability allows an authenticated low-privileged remote attacker to bypass authorization and access troubleshoot files from different domains on the same Cisco Secure FMC instance, potentiall...

CVE-2025-20302

MEDIUM CVSS 4.3 Aug 14, 2025

This vulnerability allows authenticated low-privileged users on Cisco Secure FMC to bypass authorization checks and access reports from different domains managed on the same instance. Attackers can re...

CVE-2025-20306

MEDIUM CVSS 4.9 Aug 14, 2025

This vulnerability allows authenticated administrators on Cisco Secure Firewall Management Center to execute arbitrary commands as root due to insufficient input validation in HTTP parameters. Only ad...

CVE-2025-20235

MEDIUM CVSS 6.1 Aug 14, 2025

An unauthenticated cross-site scripting (XSS) vulnerability in Cisco Secure Firewall Management Center (FMC) web interface allows remote attackers to inject malicious scripts. This could lead to sessi...

CVE-2021-34751

MEDIUM CVSS 4.3 Nov 15, 2024

This vulnerability allows authenticated low-privilege users to view sensitive configuration information in clear text through Cisco Firepower Management Center's web GUI. It affects Cisco FMC Software...

CVE-2024-20482

MEDIUM CVSS 6.5 Oct 23, 2024

This vulnerability allows authenticated users with custom read-only roles to elevate privileges on Cisco Secure Firewall Management Center devices. Attackers can modify configuration settings they sho...

CVE-2024-20472

MEDIUM CVSS 6.5 Oct 23, 2024

An authenticated SQL injection vulnerability in Cisco Secure Firewall Management Center (FMC) web interface allows administrators to execute arbitrary SQL queries. This could lead to unauthorized data...

CVE-2024-20410

MEDIUM CVSS 5.4 Oct 23, 2024

An unauthenticated cross-site scripting (XSS) vulnerability in Cisco Firepower Management Center's web interface allows remote attackers to inject malicious scripts. This could lead to session hijacki...

CVE-2024-20387

MEDIUM CVSS 5.4 Oct 23, 2024

This stored XSS vulnerability in Cisco FMC's web management interface allows authenticated attackers to inject malicious scripts that execute when other users view affected pages. It affects organizat...

CVE-2024-20374

MEDIUM CVSS 6.5 Oct 23, 2024

This vulnerability allows authenticated administrators in Cisco Secure Firewall Management Center to execute arbitrary commands as root via crafted HTTP requests due to insufficient input validation. ...

CVE-2024-20379

MEDIUM CVSS 6.5 Oct 23, 2024

This vulnerability allows authenticated remote attackers to read arbitrary files from the underlying operating system of Cisco Secure Firewall Management Center (FMC) Software. Attackers need valid us...

CVE-2024-20300

MEDIUM CVSS 4.8 Oct 23, 2024

This CVE describes a cross-site scripting (XSS) vulnerability in Cisco Firepower Management Center's web interface that allows authenticated attackers to inject malicious scripts. When exploited, it c...

CVE-2024-20275

MEDIUM CVSS 6.1 Oct 23, 2024

This vulnerability allows authenticated remote attackers with Network Administrator privileges to execute arbitrary operating system commands on Cisco Secure Firewall Management Center devices. Attack...

CVE-2024-20298

MEDIUM CVSS 4.8 Oct 23, 2024

This CVE describes a cross-site scripting (XSS) vulnerability in Cisco Firepower Management Center's web interface that allows authenticated attackers to inject malicious scripts. When exploited, it e...

CVE-2024-20273

MEDIUM CVSS 6.1 Oct 23, 2024

An unauthenticated cross-site scripting (XSS) vulnerability in Cisco Firepower Management Center's web interface allows remote attackers to inject malicious scripts. This could lead to session hijacki...