{"resultsPerPage":1,"startIndex":0,"totalResults":1,"format":"NVD_CVE","version":"2.0","timestamp":"2026-04-22T10:51:55.303","vulnerabilities":[{"cve":{"id":"CVE-2024-20340","sourceIdentifier":"psirt@cisco.com","published":"2024-10-23T17:15:18.300","lastModified":"2026-03-04T18:16:10.040","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"A vulnerability in the web-based management interface of Cisco Secure Firewall Management Center (FMC) Software, formerly Firepower Management Center Software, could allow an authenticated, remote attacker to perform an SQL injection attack against an affected device. To exploit this vulnerability, an attacker must have a valid account on the device with the role of Security Approver, Intrusion Admin, Access Admin, or Network Admin.\r\n\r This vulnerability is due to insufficient validation of user-supplied input. An attacker could exploit this vulnerability by sending a crafted HTTP request to the web-based management interface of an affected device. A successful exploit could allow the attacker to read the contents of databases on the affected device and also obtain limited read access to the underlying operating system."},{"lang":"es","value":"Una vulnerabilidad en la interfaz de administración basada en web del software Cisco Secure Firewall Management Center (FMC), anteriormente Firepower Management Center Software, podría permitir que un atacante remoto autenticado realice un ataque de inyección SQL contra un dispositivo afectado. Para aprovechar esta vulnerabilidad, un atacante debe tener una cuenta válida en el dispositivo con el rol de aprobador de seguridad, administrador de intrusiones, administrador de acceso o administrador de red. Esta vulnerabilidad se debe a una validación insuficiente de la entrada proporcionada por el usuario. Un atacante podría aprovechar esta vulnerabilidad enviando una solicitud HTTP manipulada a la interfaz de administración basada en web de un dispositivo afectado. Una explotación exitosa podría permitir al atacante leer el contenido de las bases de datos en el dispositivo afectado y también obtener acceso de lectura limitado al sistema operativo subyacente."}],"metrics":{"cvssMetricV31":[{"source":"psirt@cisco.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N","baseScore":6.5,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":3.6},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N","baseScore":6.5,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":3.6}]},"weaknesses":[{"source":"psirt@cisco.com","type":"Secondary","description":[{"lang":"en","value":"CWE-89"}]},{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-89"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:cisco:secure_firewall_management_center:7.0.0:*:*:*:*:*:*:*","matchCriteriaId":"DFA94312-376E-4785-888F-3C07612E1DF7"},{"vulnerable":true,"criteria":"cpe:2.3:a:cisco:secure_firewall_management_center:7.0.0.1:*:*:*:*:*:*:*","matchCriteriaId":"29E73FBF-2579-4660-AFFA-7F9607004226"},{"vulnerable":true,"criteria":"cpe:2.3:a:cisco:secure_firewall_management_center:7.0.1:*:*:*:*:*:*:*","matchCriteriaId":"87FAAFFB-0589-441B-8289-8B8A6E18F705"},{"vulnerable":true,"criteria":"cpe:2.3:a:cisco:secure_firewall_management_center:7.0.1.1:*:*:*:*:*:*:*","matchCriteriaId":"73B92119-793D-4A43-A056-24DB6826E759"},{"vulnerable":true,"criteria":"cpe:2.3:a:cisco:secure_firewall_management_center:7.0.2:*:*:*:*:*:*:*","matchCriteriaId":"093A0BC2-037C-463F-AFC5-EF11C2954EAD"},{"vulnerable":true,"criteria":"cpe:2.3:a:cisco:secure_firewall_management_center:7.0.2.1:*:*:*:*:*:*:*","matchCriteriaId":"C4F434FC-CAA4-4DBB-8094-C4ECC28B31E7"},{"vulnerable":true,"criteria":"cpe:2.3:a:cisco:secure_firewall_management_center:7.0.3:*:*:*:*:*:*:*","matchCriteriaId":"68C70BB3-33B3-4E7E-99D5-FF76D4ED96AE"},{"vulnerable":true,"criteria":"cpe:2.3:a:cisco:secure_firewall_management_center:7.0.4:*:*:*:*:*:*:*","matchCriteriaId":"B881B8DF-A96D-4B64-B98A-71F0D3388641"},{"vulnerable":true,"criteria":"cpe:2.3:a:cisco:secure_firewall_management_center:7.0.5:*:*:*:*:*:*:*","matchCriteriaId":"F6A97625-D39C-42D5-89E4-415A868A0972"},{"vulnerable":true,"criteria":"cpe:2.3:a:cisco:secure_firewall_management_center:7.0.6:*:*:*:*:*:*:*","matchCriteriaId":"5E4D83B4-9697-4071-AC9F-7ADC86A6B529"},{"vulnerable":true,"criteria":"cpe:2.3:a:cisco:secure_firewall_management_center:7.0.6.1:*:*:*:*:*:*:*","matchCriteriaId":"8F81F708-ACED-4E42-8CA9-116B5C4F5141"},{"vulnerable":true,"criteria":"cpe:2.3:a:cisco:secure_firewall_management_center:7.0.6.2:*:*:*:*:*:*:*","matchCriteriaId":"3C86116B-8475-40A0-A507-D4A7947F5F2C"},{"vulnerable":true,"criteria":"cpe:2.3:a:cisco:secure_firewall_management_center:7.1.0:*:*:*:*:*:*:*","matchCriteriaId":"A58A2DA5-3EE7-408D-AAFA-82330F0325B2"},{"vulnerable":true,"criteria":"cpe:2.3:a:cisco:secure_firewall_management_center:7.1.0.1:*:*:*:*:*:*:*","matchCriteriaId":"7FA98EEC-2059-4CA9-92F1-72C1E0BB7EC6"},{"vulnerable":true,"criteria":"cpe:2.3:a:cisco:secure_firewall_management_center:7.1.0.2:*:*:*:*:*:*:*","matchCriteriaId":"F4C51EE7-866B-410C-B75E-EF260D5062B0"},{"vulnerable":true,"criteria":"cpe:2.3:a:cisco:secure_firewall_management_center:7.1.0.3:*:*:*:*:*:*:*","matchCriteriaId":"5F1FFD07-B874-4D3C-8E2C-9A204F1E994E"},{"vulnerable":true,"criteria":"cpe:2.3:a:cisco:secure_firewall_management_center:7.2.0:*:*:*:*:*:*:*","matchCriteriaId":"FB5ACB9E-86AF-4EC1-9F36-A202429CD0F4"},{"vulnerable":true,"criteria":"cpe:2.3:a:cisco:secure_firewall_management_center:7.2.0.1:*:*:*:*:*:*:*","matchCriteriaId":"AD1E4527-AAE2-4DA9-AFDA-6375839F7843"},{"vulnerable":true,"criteria":"cpe:2.3:a:cisco:secure_firewall_management_center:7.2.1:*:*:*:*:*:*:*","matchCriteriaId":"2F0AF047-EAE9-4C77-BCEF-5CB26F84C742"},{"vulnerable":true,"criteria":"cpe:2.3:a:cisco:secure_firewall_management_center:7.2.2:*:*:*:*:*:*:*","matchCriteriaId":"2ED03874-4071-4382-8A46-8B3A59E601FF"},{"vulnerable":true,"criteria":"cpe:2.3:a:cisco:secure_firewall_management_center:7.2.3:*:*:*:*:*:*:*","matchCriteriaId":"BF84E043-DF3C-4A95-8FDA-B0FDCD795377"},{"vulnerable":true,"criteria":"cpe:2.3:a:cisco:secure_firewall_management_center:7.2.3.1:*:*:*:*:*:*:*","matchCriteriaId":"B9498087-9642-4A86-B3EE-1513C55A86E2"},{"vulnerable":true,"criteria":"cpe:2.3:a:cisco:secure_firewall_management_center:7.2.4:*:*:*:*:*:*:*","matchCriteriaId":"36C229AB-2851-48D4-815A-63AAB4462A24"},{"vulnerable":true,"criteria":"cpe:2.3:a:cisco:secure_firewall_management_center:7.2.4.1:*:*:*:*:*:*:*","matchCriteriaId":"6DA4BCFC-8237-4F5C-9863-523EE7D8619B"},{"vulnerable":true,"criteria":"cpe:2.3:a:cisco:secure_firewall_management_center:7.2.5:*:*:*:*:*:*:*","matchCriteriaId":"07693A92-7D84-45A1-ACD6-D83AE41D504B"},{"vulnerable":true,"criteria":"cpe:2.3:a:cisco:secure_firewall_management_center:7.2.5.1:*:*:*:*:*:*:*","matchCriteriaId":"2C78050A-A5FB-427B-BF0D-0353B240A4FF"},{"vulnerable":true,"criteria":"cpe:2.3:a:cisco:secure_firewall_management_center:7.2.5.2:*:*:*:*:*:*:*","matchCriteriaId":"85E76AE7-12AC-4419-AE66-43730B173B4E"},{"vulnerable":true,"criteria":"cpe:2.3:a:cisco:secure_firewall_management_center:7.2.6:*:*:*:*:*:*:*","matchCriteriaId":"4D803EC9-26EE-4799-A435-C782C92739CF"},{"vulnerable":true,"criteria":"cpe:2.3:a:cisco:secure_firewall_management_center:7.2.7:*:*:*:*:*:*:*","matchCriteriaId":"6EEF87CD-2335-4886-A65C-4E33775AEC52"},{"vulnerable":true,"criteria":"cpe:2.3:a:cisco:secure_firewall_management_center:7.2.8:*:*:*:*:*:*:*","matchCriteriaId":"953EB81A-1B53-4A57-9F59-D4A7D37E657E"},{"vulnerable":true,"criteria":"cpe:2.3:a:cisco:secure_firewall_management_center:7.2.8.1:*:*:*:*:*:*:*","matchCriteriaId":"1CB534BC-3E4D-4484-AFD0-69524B1F07F9"},{"vulnerable":true,"criteria":"cpe:2.3:a:cisco:secure_firewall_management_center:7.3.0:*:*:*:*:*:*:*","matchCriteriaId":"5D401072-6709-4921-8918-720F28D61E24"},{"vulnerable":true,"criteria":"cpe:2.3:a:cisco:secure_firewall_management_center:7.3.1:*:*:*:*:*:*:*","matchCriteriaId":"C0EA3467-4205-4C41-AF24-689330F7396B"},{"vulnerable":true,"criteria":"cpe:2.3:a:cisco:secure_firewall_management_center:7.3.1.1:*:*:*:*:*:*:*","matchCriteriaId":"9BE94E38-5F29-4AE1-8129-7F7582C2CC75"},{"vulnerable":true,"criteria":"cpe:2.3:a:cisco:secure_firewall_management_center:7.3.1.2:*:*:*:*:*:*:*","matchCriteriaId":"FEF603AD-D69B-4DD8-A7F4-6BEFD355EF29"},{"vulnerable":true,"criteria":"cpe:2.3:a:cisco:secure_firewall_management_center:7.4.0:*:*:*:*:*:*:*","matchCriteriaId":"D6BD1665-7824-4D98-A930-432CBDA4EAD5"},{"vulnerable":true,"criteria":"cpe:2.3:a:cisco:secure_firewall_management_center:7.4.1:*:*:*:*:*:*:*","matchCriteriaId":"F8056E69-22FA-4935-A576-916805D90C62"},{"vulnerable":true,"criteria":"cpe:2.3:a:cisco:secure_firewall_management_center:7.4.1.1:*:*:*:*:*:*:*","matchCriteriaId":"6A80BBBE-DB5E-460A-8621-6E28D2BD6E44"},{"vulnerable":true,"criteria":"cpe:2.3:a:cisco:secure_firewall_management_center:7.4.2:*:*:*:*:*:*:*","matchCriteriaId":"2B33F953-FEF3-4C46-A12A-2A42D8339D6E"}]}]}],"references":[{"url":"https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-fmc-sql-inject-2EnmTC8v","source":"psirt@cisco.com","tags":["Vendor Advisory"]}]}}]}