CVE-2020-3456
Cisco FXOS Software Firepower Chassis Manager Cross-Site Request Forgery Vulnerability
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
A vulnerability in the Cisco Firepower Chassis Manager (FCM) of Cisco FXOS Software could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack against a user of an affected device. The vulnerability is due to insufficient CSRF protections for the FCM interface. An attacker could exploit this vulnerability by persuading a targeted user to click a malicious link. A successful exploit could allow the attacker to send arbitrary requests that could take unauthorized actions on behalf of the targeted user.
Una vulnerabilidad en Cisco Firepower Chassis Manager (FCM) de Cisco FXOS Software, podría permitir a un atacante remoto no autenticado conducir un ataque de tipo cross-site request forgery (CSRF) contra un usuario de un dispositivo afectado. La vulnerabilidad es debido a protecciones de CSRF insuficientes para la interfaz FCM. Un atacante podría explotar esta vulnerabilidad al persuadir a un usuario objetivo para que haga clic en un enlace malicioso. Una explotación con éxito podría permitir a un atacante enviar peticiones arbitrarias que podrían tomar acciones no autorizadas en nombre del usuario objetivo
CVSS Scores
SSVC
- Decision:Track*
Timeline
- 2019-12-12 CVE Reserved
- 2020-10-21 CVE Published
- 2024-07-08 EPSS Updated
- 2024-11-13 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-352: Cross-Site Request Forgery (CSRF)
CAPEC
References (1)
URL | Tag | Source |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-fxosfcm-csrf-uhO4e5BZ | 2023-11-07 |
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Cisco Search vendor "Cisco" | Firepower Extensible Operating System Search vendor "Cisco" for product "Firepower Extensible Operating System" | 2.4\(1.249\) Search vendor "Cisco" for product "Firepower Extensible Operating System" and version "2.4\(1.249\)" | - |
Affected
| in | Cisco Search vendor "Cisco" | Firepower 4110 Search vendor "Cisco" for product "Firepower 4110" | - | - |
Safe
|
Cisco Search vendor "Cisco" | Firepower Extensible Operating System Search vendor "Cisco" for product "Firepower Extensible Operating System" | 2.4\(1.249\) Search vendor "Cisco" for product "Firepower Extensible Operating System" and version "2.4\(1.249\)" | - |
Affected
| in | Cisco Search vendor "Cisco" | Firepower 4112 Search vendor "Cisco" for product "Firepower 4112" | - | - |
Safe
|
Cisco Search vendor "Cisco" | Firepower Extensible Operating System Search vendor "Cisco" for product "Firepower Extensible Operating System" | 2.4\(1.249\) Search vendor "Cisco" for product "Firepower Extensible Operating System" and version "2.4\(1.249\)" | - |
Affected
| in | Cisco Search vendor "Cisco" | Firepower 4115 Search vendor "Cisco" for product "Firepower 4115" | - | - |
Safe
|
Cisco Search vendor "Cisco" | Firepower Extensible Operating System Search vendor "Cisco" for product "Firepower Extensible Operating System" | 2.4\(1.249\) Search vendor "Cisco" for product "Firepower Extensible Operating System" and version "2.4\(1.249\)" | - |
Affected
| in | Cisco Search vendor "Cisco" | Firepower 4120 Search vendor "Cisco" for product "Firepower 4120" | - | - |
Safe
|
Cisco Search vendor "Cisco" | Firepower Extensible Operating System Search vendor "Cisco" for product "Firepower Extensible Operating System" | 2.4\(1.249\) Search vendor "Cisco" for product "Firepower Extensible Operating System" and version "2.4\(1.249\)" | - |
Affected
| in | Cisco Search vendor "Cisco" | Firepower 4125 Search vendor "Cisco" for product "Firepower 4125" | - | - |
Safe
|
Cisco Search vendor "Cisco" | Firepower Extensible Operating System Search vendor "Cisco" for product "Firepower Extensible Operating System" | 2.4\(1.249\) Search vendor "Cisco" for product "Firepower Extensible Operating System" and version "2.4\(1.249\)" | - |
Affected
| in | Cisco Search vendor "Cisco" | Firepower 4140 Search vendor "Cisco" for product "Firepower 4140" | - | - |
Safe
|
Cisco Search vendor "Cisco" | Firepower Extensible Operating System Search vendor "Cisco" for product "Firepower Extensible Operating System" | 2.4\(1.249\) Search vendor "Cisco" for product "Firepower Extensible Operating System" and version "2.4\(1.249\)" | - |
Affected
| in | Cisco Search vendor "Cisco" | Firepower 4145 Search vendor "Cisco" for product "Firepower 4145" | - | - |
Safe
|
Cisco Search vendor "Cisco" | Firepower Extensible Operating System Search vendor "Cisco" for product "Firepower Extensible Operating System" | 2.4\(1.249\) Search vendor "Cisco" for product "Firepower Extensible Operating System" and version "2.4\(1.249\)" | - |
Affected
| in | Cisco Search vendor "Cisco" | Firepower 4150 Search vendor "Cisco" for product "Firepower 4150" | - | - |
Safe
|
Cisco Search vendor "Cisco" | Firepower Extensible Operating System Search vendor "Cisco" for product "Firepower Extensible Operating System" | 2.4\(1.249\) Search vendor "Cisco" for product "Firepower Extensible Operating System" and version "2.4\(1.249\)" | - |
Affected
| in | Cisco Search vendor "Cisco" | Firepower 9300 Sm-24 Search vendor "Cisco" for product "Firepower 9300 Sm-24" | - | - |
Safe
|
Cisco Search vendor "Cisco" | Firepower Extensible Operating System Search vendor "Cisco" for product "Firepower Extensible Operating System" | 2.4\(1.249\) Search vendor "Cisco" for product "Firepower Extensible Operating System" and version "2.4\(1.249\)" | - |
Affected
| in | Cisco Search vendor "Cisco" | Firepower 9300 Sm-36 Search vendor "Cisco" for product "Firepower 9300 Sm-36" | - | - |
Safe
|
Cisco Search vendor "Cisco" | Firepower Extensible Operating System Search vendor "Cisco" for product "Firepower Extensible Operating System" | 2.4\(1.249\) Search vendor "Cisco" for product "Firepower Extensible Operating System" and version "2.4\(1.249\)" | - |
Affected
| in | Cisco Search vendor "Cisco" | Firepower 9300 Sm-40 Search vendor "Cisco" for product "Firepower 9300 Sm-40" | - | - |
Safe
|
Cisco Search vendor "Cisco" | Firepower Extensible Operating System Search vendor "Cisco" for product "Firepower Extensible Operating System" | 2.4\(1.249\) Search vendor "Cisco" for product "Firepower Extensible Operating System" and version "2.4\(1.249\)" | - |
Affected
| in | Cisco Search vendor "Cisco" | Firepower 9300 Sm-44 Search vendor "Cisco" for product "Firepower 9300 Sm-44" | - | - |
Safe
|
Cisco Search vendor "Cisco" | Firepower Extensible Operating System Search vendor "Cisco" for product "Firepower Extensible Operating System" | 2.4\(1.249\) Search vendor "Cisco" for product "Firepower Extensible Operating System" and version "2.4\(1.249\)" | - |
Affected
| in | Cisco Search vendor "Cisco" | Firepower 9300 Sm-44 X 3 Search vendor "Cisco" for product "Firepower 9300 Sm-44 X 3" | - | - |
Safe
|
Cisco Search vendor "Cisco" | Firepower Extensible Operating System Search vendor "Cisco" for product "Firepower Extensible Operating System" | 2.4\(1.249\) Search vendor "Cisco" for product "Firepower Extensible Operating System" and version "2.4\(1.249\)" | - |
Affected
| in | Cisco Search vendor "Cisco" | Firepower 9300 Sm-48 Search vendor "Cisco" for product "Firepower 9300 Sm-48" | - | - |
Safe
|
Cisco Search vendor "Cisco" | Firepower Extensible Operating System Search vendor "Cisco" for product "Firepower Extensible Operating System" | 2.4\(1.249\) Search vendor "Cisco" for product "Firepower Extensible Operating System" and version "2.4\(1.249\)" | - |
Affected
| in | Cisco Search vendor "Cisco" | Firepower 9300 Sm-56 Search vendor "Cisco" for product "Firepower 9300 Sm-56" | - | - |
Safe
|
Cisco Search vendor "Cisco" | Firepower Extensible Operating System Search vendor "Cisco" for product "Firepower Extensible Operating System" | 2.4\(1.249\) Search vendor "Cisco" for product "Firepower Extensible Operating System" and version "2.4\(1.249\)" | - |
Affected
| in | Cisco Search vendor "Cisco" | Firepower 9300 Sm-56 X 3 Search vendor "Cisco" for product "Firepower 9300 Sm-56 X 3" | - | - |
Safe
|