Vulnslist

find the latest Cisco vulnerabilities

Cisco Firepower Management Center Software Object Group Access Control List Bypass Vulnerability

cisco-sa-fmc-object-bypass-fTH8tDjq · Medium · Published · Updated

A vulnerability in the Object Groups for Access Control Lists (ACLs) feature of Cisco Firepower Management Center (FMC) Software could allow an unauthenticated, remote attacker to bypass configured access controls on managed devices that are running Cisco Firepower Threat Defense (FTD) Software. This vulnerability is due to the incorrect deployment of the Object Groups for ACLs feature from Cisco FMC Software to managed FTD devices in high-availability setups. After an affected device is rebooted following Object Groups for ACLs deployment, an attacker can exploit this vulnerability by sending traffic through the affected device. A successful exploit could allow the attacker to bypass configured access controls and successfully send traffic to devices that are expected to be protected by the affected device.  Cisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability. This advisory is available at the following link:https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-fmc-object-bypass-fTH8tDjq This advisory is part of the May 2024 release of the Cisco ASA, FMC, and FTD Software Security Advisory Bundled Publication. For a complete list of the advisories and links to them, see Cisco Event Response: May 2024 Semiannual Cisco ASA, FMC, and FTD Software Security Advisory Bundled Publication.

Workarounds

There are no workarounds that address this vulnerability.

CVEsCVE-2024-20361
Cisco Bug IDsCSCwd66820
CVSS ScoreBase 5.8
Base 5.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:L/A:N/E:X/RL:X/RC:X
Product Names From Source
Cisco Firepower Threat Defense Software, Cisco Firepower Management Center 7.1.0, Cisco Firepower Management Center 7.1.0.1, Cisco Firepower Management Center 7.1.0.2, Cisco Firepower Management Center 7.1.0.3, Cisco Firepower Management Center 7.2.0, Cisco Firepower Management Center 7.2.1, Cisco Firepower Management Center 7.2.2, Cisco Firepower Management Center 7.2.0.1, Cisco Firepower Management Center 7.2.3, Cisco Firepower Management Center 7.2.3.1, Cisco Firepower Management Center 7.3.0, Cisco Firepower Management Center 7.3.1, Cisco Secure Firewall Management Center (FMC), Cisco Secure Firewall Threat Defense (FTD) Software, Cisco Secure Firewall Management Center (FMC) Appliances

Related Products

Product CVE Evidence
Cisco Secure Firewall Threat Defense (FTD) Software CVE-2024-20361 Cisco OpenVuln
Cisco Secure Firewall Management Center (FMC) Appliances CVE-2024-20361 Cisco OpenVuln
Cisco Secure Firewall Management Center (FMC) CVE-2024-20361 Cisco OpenVuln
Cisco Firepower Threat Defense Software CVE-2024-20361 Cisco OpenVuln
Cisco Firepower Management Center CVE-2024-20361 Cisco OpenVuln