Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2020-3558


A vulnerability in the web-based management interface of Cisco Firepower Management Center (FMC) Software could allow an unauthenticated, remote attacker to redirect a user to a malicious web page. The vulnerability is due to improper input validation of the parameters of an HTTP request. An attacker could exploit this vulnerability by intercepting an HTTP request from a user. A successful exploit could allow the attacker to modify the HTTP request to cause the interface to redirect the user to a specific, malicious URL. This type of vulnerability is known as an open redirect attack and is used in phishing attacks that get users to unknowingly visit malicious sites.


Published

2020-10-21T19:15:17.700

Last Modified

2024-11-26T16:09:02.407

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 4.7 (MEDIUM)

CVSSv2 Vector

AV:N/AC:M/Au:N/C:P/I:P/A:N

  • Access Vector: NETWORK
  • Access Complexity: MEDIUM
  • Authentication: NONE
  • Confidentiality Impact: PARTIAL
  • Integrity Impact: PARTIAL
  • Availability Impact: NONE
Exploitability Score

8.6

Impact Score

4.9

Weaknesses
  • Type: Secondary
    CWE-601
  • Type: Primary
    CWE-601

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application cisco secure_firewall_management_center ≤ 6.2.3.16 Yes
Application cisco secure_firewall_management_center ≤ 6.3.0.5 Yes
Application cisco secure_firewall_management_center ≤ 6.4.0.9 Yes
Application cisco secure_firewall_management_center ≤ 6.5.0.4 Yes

References