CVE-2022-20627: Cisco Firepower Management Center Software Cross-Site Scripting Vulnerabilities
Multiple vulnerabilities in the web-based management interface of Cisco Firepower Management Center (FMC) Software could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface. These vulnerabilities are due to insufficient validation of user-supplied input by the web-based management interface. An attacker could exploit these vulnerabilities by persuading a user of the interface to click a crafted link. A successful exploit could allow the attacker to execute arbitrary script code in the context of the interface or access sensitive, browser-based information.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID?
The vulnerability ID is CVE-2022-20627.
What is the title of the vulnerability?
The title of the vulnerability is 'Multiple vulnerabilities in the web-based management interface of Cisco Firepower Management Center'.
What is the severity of CVE-2022-20627?
The severity of CVE-2022-20627 is medium with a CVSS score of 5.4.
What is the affected software?
The affected software is Cisco Firepower Management Center versions 6.4.0.15 to 6.6.5.2 and versions 6.7.0 to 7.0.2.
How can an attacker exploit this vulnerability?
An authenticated, remote attacker can exploit this vulnerability to conduct a cross-site scripting (XSS) attack against a user of the web-based management interface.