Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2024-20361


A vulnerability in the Object Groups for Access Control Lists (ACLs) feature of Cisco Firepower Management Center (FMC) Software could allow an unauthenticated, remote attacker to bypass configured access controls on managed devices that are running Cisco Firepower Threat Defense (FTD) Software. This vulnerability is due to the incorrect deployment of the Object Groups for ACLs feature from Cisco FMC Software to managed FTD devices in high-availability setups. After an affected device is rebooted following Object Groups for ACLs deployment, an attacker can exploit this vulnerability by sending traffic through the affected device. A successful exploit could allow the attacker to bypass configured access controls and successfully send traffic to devices that are expected to be protected by the affected device.


Published

2024-05-22T17:16:13.733

Last Modified

2025-08-07T17:08:51.217

Status

Analyzed

Source

[email protected]

Severity

CVSSv3.1: 5.8 (MEDIUM)

Weaknesses
  • Type: Secondary
    CWE-264

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application cisco secure_firewall_management_center 7.1.0 Yes
Application cisco secure_firewall_management_center 7.1.0.1 Yes
Application cisco secure_firewall_management_center 7.1.0.2 Yes
Application cisco secure_firewall_management_center 7.1.0.3 Yes
Application cisco secure_firewall_management_center 7.2.0 Yes
Application cisco secure_firewall_management_center 7.2.0.1 Yes
Application cisco secure_firewall_management_center 7.2.1 Yes
Application cisco secure_firewall_management_center 7.2.2 Yes
Application cisco secure_firewall_management_center 7.2.3 Yes
Application cisco secure_firewall_management_center 7.2.3.1 Yes
Application cisco secure_firewall_management_center 7.3.0 Yes
Application cisco secure_firewall_management_center 7.3.1 Yes

References