4.3
CVSSv3

CVE-2022-20938

Published: 15/11/2022 Updated: 25/01/2024
CVSS v3 Base Score: 4.3 | Impact Score: 1.4 | Exploitability Score: 2.8
VMScore: 0

Vulnerability Summary

A vulnerability in the module import function of the administrative interface of Cisco Firepower Management Center (FMC) Software could allow an authenticated, remote malicious user to view sensitive information. This vulnerability is due to insufficient validation of the XML syntax when importing a module. An attacker could exploit this vulnerability by supplying a specially crafted XML file to the function. A successful exploit could allow the malicious user to read sensitive data that would normally not be revealed.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

cisco firepower management center 6.1.0.2

cisco firepower management center 6.2.0.2

cisco firepower management center 6.2.1

cisco firepower management center 6.1.0

cisco firepower management center 6.2.0

cisco firepower management center 6.1.0.3

cisco firepower management center 6.1.0.6

cisco firepower management center 6.2.2

cisco firepower management center 6.2.3

cisco firepower management center 6.2.0.5

cisco firepower management center 6.2.2.2

cisco firepower management center 6.1.0.7

cisco firepower management center 6.3.0

cisco firepower management center 6.2.2.1

cisco firepower management center 6.2.3.6

cisco firepower management center 6.4.0

cisco firepower management center 6.2.3.1

cisco firepower management center 6.2.3.2

cisco firepower management center 6.5.0

cisco firepower management center 6.2.3.10

cisco firepower management center 6.6.0.1

cisco firepower management center 6.6.0

cisco firepower management center 7.1.0.2

cisco firepower management center 6.7.0

cisco firepower management center 7.1.0

cisco firepower management center 7.0.0

cisco firepower management center 7.1.0.1

cisco firepower management center 6.4.0.15

cisco firepower management center 6.6.3

cisco firepower management center 6.6.4

cisco firepower management center 6.6.5

cisco firepower management center 6.6.5.1

cisco firepower management center 6.6.5.2

cisco firepower management center 6.6.1

cisco firepower management center 7.0.0.1

cisco firepower management center 7.0.1

cisco firepower management center 7.0.1.1

cisco firepower management center 7.0.2

cisco firepower management center 7.0.2.1

cisco firepower management center 7.0.3

cisco firepower management center 7.0.4

cisco firepower management center 6.7.0.1

cisco firepower management center 6.7.0.3

cisco firepower management center 6.5.0.1

cisco firepower management center 6.5.0.5

cisco firepower management center 6.4.0.14

cisco firepower management center 6.4.0.13

cisco firepower management center 6.1.0.1

cisco firepower management center 6.1.0.4

cisco firepower management center 6.1.0.5

cisco firepower management center 6.2.0.1

cisco firepower management center 6.2.0.3

cisco firepower management center 6.2.0.4

cisco firepower management center 6.2.0.6

cisco firepower management center 6.2.2.3

cisco firepower management center 6.2.2.4

cisco firepower management center 6.2.2.5

cisco firepower management center 6.2.3.3

cisco firepower management center 6.2.3.4

cisco firepower management center 6.2.3.5

cisco firepower management center 6.2.3.7

cisco firepower management center 6.2.3.9

cisco firepower management center 6.2.3.11

cisco firepower management center 6.2.3.12

cisco firepower management center 6.2.3.13

cisco firepower management center 6.2.3.14

cisco firepower management center 6.2.3.15

cisco firepower management center 6.2.3.16

cisco firepower management center 6.5.0.2

cisco firepower management center 6.5.0.3

cisco firepower management center 6.5.0.4

cisco firepower management center 6.2.3.17

cisco firepower management center 6.2.3.18

cisco firepower management center 6.7.0.2

cisco firepower management center 6.3.0.1

cisco firepower management center 6.3.0.2

cisco firepower management center 6.3.0.3

cisco firepower management center 6.3.0.4

cisco firepower management center 6.3.0.5

cisco firepower management center 6.4.0.1

cisco firepower management center 6.4.0.2

cisco firepower management center 6.4.0.3

cisco firepower management center 6.4.0.4

cisco firepower management center 6.4.0.5

cisco firepower management center 6.4.0.7

cisco firepower management center 6.4.0.8

cisco firepower management center 6.4.0.9

cisco firepower management center 6.4.0.10

cisco firepower management center 6.4.0.11

cisco firepower management center 6.4.0.12

cisco firepower management center 6.2.3.8

cisco firepower management center 6.4.0.6

Vendor Advisories

A vulnerability in the module import function of the administrative interface of Cisco Firepower Management Center (FMC) Software could allow an authenticated, remote attacker to view sensitive information This vulnerability is due to insufficient validation of the XML syntax when importing a module An attacker could exploit this vulnerability by ...