CVE-2024-20424

Published Oct 23, 2024

Last updated 16 days ago

Overview

Description
A vulnerability in the web-based management interface of Cisco Secure Firewall Management Center (FMC) Software, formerly Firepower Management Center Software, could allow an authenticated, remote attacker to execute arbitrary commands on the underlying operating system as root. This vulnerability is due to insufficient input validation of certain HTTP requests. An attacker could exploit this vulnerability by authenticating to the web-based management interface of an affected device and then sending a crafted HTTP request to the device. A successful exploit could allow the attacker to execute arbitrary commands with root permissions on the underlying operating system of the Cisco FMC device or to execute commands on managed Cisco Firepower Threat Defense (FTD) devices. To exploit this vulnerability, the attacker would need valid credentials for a user account with at least the role of Security Analyst (Read Only).
Source
ykramarz@cisco.com
NVD status
Analyzed

Risk scores

CVSS 3.1

Type
Primary
Base score
9.9
Impact score
6
Exploitability score
3.1
Vector string
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Severity
CRITICAL

Weaknesses

nvd@nist.gov
CWE-78
ykramarz@cisco.com
CWE-78

Social media

Hype score
Not currently trending
  1. Cisco FMC の脆弱性 CVE-2024-20424 が FIX:CVSS 9.9 のコマンド・インジェクション https://t.co/VIzTzg5aYT #Cisco #CiscoFMC #commandInjection #FMC #Vulnerability

    @iototsecnews

    1 Nov 2024

    37 Impressions

    1 Retweet

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  2. CVE number = CVE-2024-20424 A vulnerability in the web-based management interface of Cisco Secure Firewall Management Center (FMC) Software, formerly Firepower Management Center Software, could allowan authenticated, remote attacker to execute #Cisco https://t.co/aMoGlIOu8P

    @SystemTek_UK

    26 Oct 2024

    48 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  3. 3/6 Cisco also patched three other critical vulnerabilities: - CVE-2024-20412: Static accounts with hard-coded passwords in FTD. - CVE-2024-20424: Command injection in FMC. - CVE-2024-20329: Command injection in ASA SSH. #cybersecurity #infosec #Cisco #ASA #FTD #vulnerability

    @Eth1calHackrZ

    26 Oct 2024

    39 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  4. #StegaIntelligence Cisco ZeroDays Flaws 👁️‍🗨️ CVE-2024-20424 (CVSS 9.9) en FMC permite que un atacante remoto autenticado envíe solicitudes HTTP especialmente diseñadas que no están validadas adecuadamente para ejecutar comandos arbitrarios con privilegios de root en el siste

    @stegaintell

    24 Oct 2024

    40 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  5. Cisco Secure Firewall Management Center Software Command Injection Vulnerability (CVE-2024-20424) https://t.co/Uh3zywa4yc #patchmanagement

    @eyalestrin

    24 Oct 2024

    10 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  6. CVE-2024-20424 (CVSS 9.9): Cisco FMC Software Vulnerability Grants Attackers Root Access https://t.co/MVznKcbd6x

    @Dinosn

    24 Oct 2024

    2425 Impressions

    10 Retweets

    22 Likes

    5 Bookmarks

    0 Replies

    0 Quotes

  7. [CVE-2024-20424: CRITICAL] Critical vulnerability in Cisco Secure Firewall Management Center Software allows remote attackers to run commands as root. Update to patch this flaw immediately.#cybersecurity,#vulnerability https://t.co/J1OngvKYN1 https://t.co/iLcCnejBIG

    @CveFindCom

    23 Oct 2024

    29 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

Configurations