Boletines de Vulnerabilidades

Cisco Firepower Management Center Software Information Disclosure Vulnerability


Información sobre el sistema

   
Software afectado Cisco

Descripción

A vulnerability in the web-based management interface of Cisco Firepower Management Center (FMC) Software could allow an unauthenticated, remote attacker to access sensitive information. This vulnerability is due to missing authorization for certain resources in the web-based management interface together with insufficient entropy in these resource names. An attacker could exploit this vulnerability by sending a series of HTTPS requests to an affected device to enumerate resources on the

More info:

https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-fmc-info-disc-UghNRRhP?vs_f=Cisco%20Security%20Advisory&vs_cat=Security%20Intelligence&vs_type=RSS&vs_p=Cisco%20Firepower%20Management%20Center%20Software%20Information%20Disclosure%20Vulnerability&vs_k=1

Identificadores estándar

Propiedad Valor
CVE CVE-2022-20941.

Histórico de versiones

Versión Comentario Fecha
1.0 Advisory issued 2022-12-23

Miembros de

Ministerio de Defensa
CNI
CCN
CCN-CERT