A vulnerability in the web-based management interface of Cisco Firepower Management Center (FMC) Software could allow an unauthenticated, remote attacker to redirect a user to a malicious web page. The vulnerability is due to improper input validation of the parameters of an HTTP request. An attacker could exploit this vulnerability by intercepting an HTTP request from a user. A successful exploit could allow the attacker to modify the HTTP request to cause the interface to redirect the user to a specific, malicious URL. This type of vulnerability is known as an open redirect attack and is used in phishing attacks that get users to unknowingly visit malicious sites.
2020-10-21T19:15:17.700
2024-11-26T16:09:02.407
Modified
CVSSv3.1: 4.7 (MEDIUM)
AV:N/AC:M/Au:N/C:P/I:P/A:N
8.6
4.9
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | cisco | secure_firewall_management_center | ≤ 6.2.3.16 | Yes |
Application | cisco | secure_firewall_management_center | ≤ 6.3.0.5 | Yes |
Application | cisco | secure_firewall_management_center | ≤ 6.4.0.9 | Yes |
Application | cisco | secure_firewall_management_center | ≤ 6.5.0.4 | Yes |