CVE-2024-20364: XSS
A vulnerability in the web-based management interface of Cisco Firepower Management Center (FMC) Software could allow an authenticated, remote attacker to conduct a stored cross-site scripting (XSS) attack against a user of the interface of an affected device. This vulnerability is due to insufficient validation of user-supplied input by the web-based management interface. An attacker could exploit this vulnerability by inserting crafted input into various data fields in an affected interface. A successful exploit could allow the attacker to execute arbitrary script code in the context of the interface, or access sensitive, browser-based information.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-20364?
CVE-2024-20364 has a CVSS score that indicates a high severity due to its potential for stored cross-site scripting attacks.
How do I fix CVE-2024-20364?
To mitigate CVE-2024-20364, users should upgrade to the latest patched version of Cisco Firepower Management Center Software.
Who is affected by CVE-2024-20364?
CVE-2024-20364 affects authenticated users of the web-based management interface of Cisco Firepower Management Center versions 6.7.0 and 7.x.
What kind of attack can be executed through CVE-2024-20364?
CVE-2024-20364 can be exploited to perform stored cross-site scripting (XSS) attacks on the affected web management interface.
Is user authentication required to exploit CVE-2024-20364?
Yes, exploiting CVE-2024-20364 requires user authentication to the Cisco Firepower Management Center interface.