A vulnerability in the Cisco Firepower Chassis Manager (FCM) of Cisco FXOS Software could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack against a user of an affected device. The vulnerability is due to insufficient CSRF protections for the FCM interface. An attacker could exploit this vulnerability by persuading a targeted user to click a malicious link. A successful exploit could allow the attacker to send arbitrary requests that could take unauthorized actions on behalf of the targeted user.
2020-10-21T19:15:16.263
2024-11-21T05:31:06.343
Modified
CVSSv3.1: 8.8 (HIGH)
AV:N/AC:M/Au:N/C:P/I:P/A:P
8.6
6.4
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Operating System | cisco | firepower_extensible_operating_system | 2.4\(1.249\) | Yes |
Hardware | cisco | firepower_4110 | - | No |
Hardware | cisco | firepower_4112 | - | No |
Hardware | cisco | firepower_4115 | - | No |
Hardware | cisco | firepower_4120 | - | No |
Hardware | cisco | firepower_4125 | - | No |
Hardware | cisco | firepower_4140 | - | No |
Hardware | cisco | firepower_4145 | - | No |
Hardware | cisco | firepower_4150 | - | No |
Hardware | cisco | firepower_9300_sm-24 | - | No |
Hardware | cisco | firepower_9300_sm-36 | - | No |
Hardware | cisco | firepower_9300_sm-40 | - | No |
Hardware | cisco | firepower_9300_sm-44 | - | No |
Hardware | cisco | firepower_9300_sm-44_x_3 | - | No |
Hardware | cisco | firepower_9300_sm-48 | - | No |
Hardware | cisco | firepower_9300_sm-56 | - | No |
Hardware | cisco | firepower_9300_sm-56_x_3 | - | No |