CVE-2019-12691

A vulnerability in the web-based management interface of Cisco Firepower Management Center (FMC) Software could allow an authenticated, remote attacker to perform a directory traversal attack on an affected device. The vulnerability is due to insufficient input validation by the web-based management interface. An attacker could exploit this vulnerability by sending a crafted HTTP request to the web-based management interface. A successful exploit could allow the attacker to bypass Cisco FMC Software security restrictions and gain access to the underlying filesystem of the affected device.

Published : 2019-10-02 19:15 Updated : 2019-10-10 17:13

4.0
CVSS Score More info
Score 4.0 / 10
4.0
Vendor Product Version URI
Cisco Firepower Management Center 2.9.8 cpe:/a:cisco:firepower_management_center:2.9.8
Cisco Firepower Management Center 2.9.9 cpe:/a:cisco:firepower_management_center:2.9.9
Cisco Firepower Management Center 2.9.10 cpe:/a:cisco:firepower_management_center:2.9.10
Cisco Firepower Management Center 2.9.11 cpe:/a:cisco:firepower_management_center:2.9.11
Cisco Firepower Management Center 2.9.12 cpe:/a:cisco:firepower_management_center:2.9.12
Cisco Firepower Management Center 2.9.13 cpe:/a:cisco:firepower_management_center:2.9.13
Cisco Firepower Management Center 4.10.3.9 cpe:/a:cisco:firepower_management_center:4.10.3.9
Cisco Firepower Management Center 5.3.0.2 cpe:/a:cisco:firepower_management_center:5.3.0.2
Cisco Firepower Management Center 5.3.0.3 cpe:/a:cisco:firepower_management_center:5.3.0.3
Cisco Firepower Management Center 5.3.0.4 cpe:/a:cisco:firepower_management_center:5.3.0.4
Cisco Firepower Management Center 5.3.1.3 cpe:/a:cisco:firepower_management_center:5.3.1.3
Cisco Firepower Management Center 5.3.1.4 cpe:/a:cisco:firepower_management_center:5.3.1.4
Cisco Firepower Management Center 5.3.1.5 cpe:/a:cisco:firepower_management_center:5.3.1.5
Cisco Firepower Management Center 5.3.1.6 cpe:/a:cisco:firepower_management_center:5.3.1.6
Cisco Firepower Management Center 5.3_base cpe:/a:cisco:firepower_management_center:5.3_base
Cisco Firepower Management Center 5.4.0 cpe:/a:cisco:firepower_management_center:5.4.0
Cisco Firepower Management Center 5.4.0.2 cpe:/a:cisco:firepower_management_center:5.4.0.2
Cisco Firepower Management Center 5.4.1 cpe:/a:cisco:firepower_management_center:5.4.1
Cisco Firepower Management Center 5.4.1.1 cpe:/a:cisco:firepower_management_center:5.4.1.1
Cisco Firepower Management Center 5.4.1.2 cpe:/a:cisco:firepower_management_center:5.4.1.2
Cisco Firepower Management Center 5.4.1.3 cpe:/a:cisco:firepower_management_center:5.4.1.3
Cisco Firepower Management Center 5.4.1.4 cpe:/a:cisco:firepower_management_center:5.4.1.4
Cisco Firepower Management Center 5.4.1.5 cpe:/a:cisco:firepower_management_center:5.4.1.5
Cisco Firepower Management Center 5.4.1.6 cpe:/a:cisco:firepower_management_center:5.4.1.6
Cisco Firepower Management Center 5.4_base cpe:/a:cisco:firepower_management_center:5.4_base
Cisco Firepower Management Center 6.0.0 cpe:/a:cisco:firepower_management_center:6.0.0
Cisco Firepower Management Center 6.0.0.1 cpe:/a:cisco:firepower_management_center:6.0.0.1
Cisco Firepower Management Center 6.0.1 cpe:/a:cisco:firepower_management_center:6.0.1
Cisco Firepower Management Center 6.0_base cpe:/a:cisco:firepower_management_center:6.0_base
  1. Cisco (1) Search CVE
    1. Firepower Management Center (29) Search CVE
      1. 2.9.8
      2. 2.9.9
      3. 2.9.10
      4. 2.9.11
      5. 2.9.12
      6. 2.9.13
      7. 4.10.3.9
      8. 5.3.0.2
      9. 5.3.0.3
      10. 5.3.0.4
      11. 5.3.1.3
      12. 5.3.1.4
      13. 5.3.1.5
      14. 5.3.1.6
      15. 5.3_base
      16. 5.4.0
      17. 5.4.0.2
      18. 5.4.1
      19. 5.4.1.1
      20. 5.4.1.2
      21. 5.4.1.3
      22. 5.4.1.4
      23. 5.4.1.5
      24. 5.4.1.6
      25. 5.4_base
      26. 6.0.0
      27. 6.0.0.1
      28. 6.0.1
      29. 6.0_base

CWE

ID Name Description Links
CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') The software uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the software does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory. CVE

History of changes

Date Event
2019-10-10 17:13
2019-10-02 19:17

New CVE