CVE-2024-20379: Path Traversal
A vulnerability in the web-based management interface of Cisco Secure Firewall Management Center (FMC) Software, formerly Firepower Management Center Software, could allow an authenticated, remote attacker to read arbitrary files from the underlying operating system. This vulnerability exists because the web-based management interface does not properly validate user-supplied input. An attacker could exploit this vulnerability by sending a crafted HTTP request to an affected device. A successful exploit could allow the attacker to read arbitrary files on the underlying operating system of the affected device. The attacker would need valid user credentials to exploit this vulnerability.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-20379?
CVE-2024-20379 has a medium severity rating that allows authenticated, remote attackers to read arbitrary files.
Which software versions are affected by CVE-2024-20379?
CVE-2024-20379 affects Cisco Firepower Management Center Software versions 7.4.0, 7.4.1, 7.4.1.1 and Cisco Secure Firewall Management Center versions 7.3.0, 7.3.1, 7.3.1.1, and 7.3.1.2.
How do I fix CVE-2024-20379?
To fix CVE-2024-20379, upgrade the affected Cisco Secure Firewall Management Center Software to the latest patched version.
Can CVE-2024-20379 be exploited remotely?
Yes, CVE-2024-20379 can be exploited by remote authenticated attackers.
What kind of files can be accessed due to CVE-2024-20379?
CVE-2024-20379 allows attackers to read arbitrary files from the underlying operating system.