CVE-2022-20744: Cisco Firepower Management Center Software Information Disclosure Vulnerability
A vulnerability in the input protection mechanisms of Cisco Firepower Management Center (FMC) Software could allow an authenticated, remote attacker to view data without proper authorization. This vulnerability exists because of a protection mechanism that relies on the existence or values of a specific input. An attacker could exploit this vulnerability by modifying this input to bypass the protection mechanism and sending a crafted request to an affected device. A successful exploit could allow the attacker to view data beyond the scope of their authorization.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2022-20744.
What is the severity level of CVE-2022-20744?
CVE-2022-20744 has a severity level of medium.
What software is affected by CVE-2022-20744?
Cisco Firepower Management Center (FMC) Software up to version 7.1.0 is affected by CVE-2022-20744.
How can an attacker exploit CVE-2022-20744?
An authenticated, remote attacker can exploit CVE-2022-20744 to view data without proper authorization.
Is there a fix available for CVE-2022-20744?
A fix for CVE-2022-20744 may be provided by Cisco in their security advisory.