vendor:
Firepower Management Center
by:
Abdualhadi Khalifa
8.1
CVSS
CRITICAL
Authentication Bypass
287
CWE
Product Name: Firepower Management Center
Affected Version From: 6.2.3.18
Affected Version To: 6.6.7.1
Patch Exists: YES
Related CWE: CVE-2023-20048
CPE: a:cisco:firepower_management_center:6.2.3.18
Platforms Tested:
2023
Cisco Firepower Management Center Authentication Bypass
The Cisco Firepower Management Center (FMC) versions 6.2.3.18, 6.4.0.16, and 6.6.7.1 are vulnerable to an authentication bypass vulnerability. An attacker can exploit this issue to gain unauthorized access to the FMC web services interface without proper authentication. This vulnerability has been assigned CVE-2023-20048.
Mitigation:
To mitigate this vulnerability, it is recommended to update to a patched version of the Cisco Firepower Management Center software. Additionally, restrict network access to the FMC interface to trusted sources only.