Vulnslist

find the latest Cisco vulnerabilities

Cisco Firepower Management Center XML Entity Expansion Vulnerability

cisco-sa-fmc-xee-DFzARDcs · Medium · Published · Updated

A vulnerability in the dashboard widget of Cisco Firepower Management Center (FMC) Software could allow an authenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. The vulnerability is due to improper restrictions on XML entities. An attacker could exploit this vulnerability by crafting an XML-based widget on an affected server. A successful exploit could cause increased memory and CPU utilization, which could result in a DoS condition. Cisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability. This advisory is available at the following link:https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-fmc-xee-DFzARDcs

Workarounds

There are no workarounds that address this vulnerability.

CVEsCVE-2021-1267
Cisco Bug IDsCSCvt63027
CVSS ScoreBase 4.3
Base 4.3 CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L/E:X/RL:X/RC:X
Product Names From Source
Cisco Firepower Management Center 6.2.3, Cisco Firepower Management Center 6.2.3.1, Cisco Firepower Management Center 6.2.3.2, Cisco Firepower Management Center 6.2.3.3, Cisco Firepower Management Center 6.2.3.6, Cisco Firepower Management Center 6.2.3.7, Cisco Firepower Management Center 6.2.3.9, Cisco Firepower Management Center 6.2.3.10, Cisco Firepower Management Center 6.2.3.11, Cisco Firepower Management Center 6.2.3.13, Cisco Firepower Management Center 6.2.3.14, Cisco Firepower Management Center 6.2.3.16, Cisco Firepower Management Center 6.4.0, Cisco Firepower Management Center 6.4.0.1, Cisco Firepower Management Center 6.4.0.2, Cisco Firepower Management Center 6.4.0.4, Cisco Firepower Management Center 6.4.0.7, Cisco Firepower Management Center 6.4.0.8, Cisco Firepower Management Center 6.4.0.10, Cisco Firepower Management Center 6.6.0.1, Cisco Secure Firewall Management Center (FMC), Cisco Secure Firewall Management Center (FMC) Appliances

Related Products

Product CVE Evidence
Cisco Secure Firewall Management Center (FMC) Appliances CVE-2021-1267 Cisco OpenVuln
Cisco Secure Firewall Management Center (FMC) CVE-2021-1267 Cisco OpenVuln
Cisco Firepower Management Center CVE-2021-1267 Cisco OpenVuln