CVE-2019-12691: Cisco Firepower Management Center Directory Traversal Vulnerability
A vulnerability in the web-based management interface of Cisco Firepower Management Center (FMC) Software could allow an authenticated, remote attacker to perform a directory traversal attack on an affected device. The vulnerability is due to insufficient input validation by the web-based management interface. An attacker could exploit this vulnerability by sending a crafted HTTP request to the web-based management interface. A successful exploit could allow the attacker to bypass Cisco FMC Software security restrictions and gain access to the underlying filesystem of the affected device.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2019-12691?
CVE-2019-12691 is a vulnerability in the web-based management interface of Cisco Firepower Management Center (FMC) Software.
What is the severity of CVE-2019-12691?
The severity of CVE-2019-12691 is medium with a severity value of 4.9.
How does CVE-2019-12691 impact affected devices?
CVE-2019-12691 allows an authenticated, remote attacker to perform a directory traversal attack on an affected device.
What is the affected software version of CVE-2019-12691?
The affected software version of CVE-2019-12691 is Cisco Firepower Management Center up to version 6.2.3.
How can I fix CVE-2019-12691?
To fix CVE-2019-12691, Cisco recommends upgrading to a fixed software release.