CVE-2024-20387: XSS
A vulnerability in the web-based management interface of Cisco FMC Software could allow an authenticated, remote attacker to store malicious content for use in XSS attacks. This vulnerability is due to improper input sanitization in the web-based management interface of Cisco FMC Software. An attacker could exploit this vulnerability by persuading a user to click a malicious link. A successful exploit could allow the attacker to conduct a stored XSS attack on an affected device.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-20387?
The severity of CVE-2024-20387 is categorized as Medium due to the potential for authenticated, remote XSS attacks.
How do I fix CVE-2024-20387?
To fix CVE-2024-20387, upgrade to a patched version of Cisco FMC Software as specified in the advisory.
What products are affected by CVE-2024-20387?
CVE-2024-20387 affects several versions of Cisco Firepower Management Center and Cisco Secure Firewall Management Center software.
Can CVE-2024-20387 be exploited remotely?
Yes, CVE-2024-20387 can be exploited remotely by authenticated users to execute XSS attacks.
What is the cause of CVE-2024-20387?
CVE-2024-20387 is caused by improper input sanitization in the web-based management interface of Cisco FMC Software.