Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-2022-20744— Cisco Firepower Management Center Software Information Disclosure Vulnerability

EPSS 0.18% · P40
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2022-20744

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Cisco Firepower Management Center Software Information Disclosure Vulnerability
Source: NVD (National Vulnerability Database)
Vulnerability Description
A vulnerability in the input protection mechanisms of Cisco Firepower Management Center (FMC) Software could allow an authenticated, remote attacker to view data without proper authorization. This vulnerability exists because of a protection mechanism that relies on the existence or values of a specific input. An attacker could exploit this vulnerability by modifying this input to bypass the protection mechanism and sending a crafted request to an affected device. A successful exploit could allow the attacker to view data beyond the scope of their authorization.
Source: NVD (National Vulnerability Database)
CVSS Information
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Type
在安全决策中依赖未经信任的输入
Source: NVD (National Vulnerability Database)
Vulnerability Title
Cisco Firepower Management Center 安全漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Cisco Firepower Management Center(FMC)是美国思科(Cisco)公司的新一代防火墙管理中心软件。 Cisco Firepower Management Center (FMC)存在安全漏洞,该漏洞源于保护机制依赖于特定输入的存在或值。经过身份验证的远程攻击者可以在未经适当授权的情况下查看数据。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

VendorProductAffected VersionsCPESubscribe
CiscoCisco Firepower Management Center n/a -

II. Public POCs for CVE-2022-20744

#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2022-20744

登录查看更多情报信息。

Same Patch Batch · Cisco · 2022-05-03 · 19 CVEs total

CVE-2022-207598.8 HIGHCisco Adaptive Security Appliance Software and Firepower Threat Defense Software Web Servi
CVE-2022-207468.6 HIGHCisco Firepower Threat Defense Software TCP Proxy Denial of Service Vulnerability
CVE-2022-207158.6 HIGHCisco Adaptive Security Appliance Software and Firepower Threat Defense Software Remote Ac
CVE-2022-207518.6 HIGHCisco Firepower Threat Defense Software Snort Out of Memory Denial of Service Vulnerabilit
CVE-2022-207578.6 HIGHCisco Firepower Threat Defense Software Denial of Service Vulnerability
CVE-2022-207608.6 HIGHCisco Adaptive Security Appliance Software and Firepower Threat Defense Software DNS Inspe
CVE-2022-207678.6 HIGHCisco Firepower Threat Defense Software DNS Enforcement Denial of Service Vulnerability
CVE-2022-207458.6 HIGHCisco Adaptive Security Appliance Software and Firepower Threat Defense Software Web Servi
CVE-2022-207378.5 HIGHCisco Adaptive Security Appliance Software Clientless SSL VPN Heap Overflow Vulnerability
CVE-2022-207427.4 HIGHCisco Adaptive Security Appliance Software and Firepower Threat Defense Software IPsec IKE
CVE-2022-207436.5 MEDIUMCisco Firepower Management Center File Upload Security Bypass Vulnerability
CVE-2022-207406.1 MEDIUMCisco Firepower Management Center Software Cross-Site Scripting Vulnerability
CVE-2022-206295.4 MEDIUMCisco Firepower Management Center Software Cross-Site Scripting Vulnerabilities
CVE-2022-206285.4 MEDIUMCisco Firepower Management Center Software Cross-Site Scripting Vulnerabilities
CVE-2022-206275.4 MEDIUMCisco Firepower Management Center Software Cross-Site Scripting Vulnerabilities
CVE-2022-207485.3 MEDIUMCisco Firepower Threat Defense Software Local Malware Analysis Denial of Service Vulnerabi
CVE-2022-207294.4 MEDIUMCisco Firepower Threat Defense Software XML Injection Vulnerability
CVE-2022-207304.0 MEDIUMCisco Firepower Threat Defense Software Security Intelligence DNS Feed Bypass Vulnerabilit

IV. Related Vulnerabilities

V. Comments for CVE-2022-20744

No comments yet


Leave a comment