A vulnerability in an access control mechanism of Cisco Firepower Management Center (FMC) Software could allow an authenticated, remote attacker to access services beyond the scope of their authorization. This vulnerability is due to insufficient enforcement of access control in the affected software. An attacker could exploit this vulnerability by directly accessing the internal services of an affected device. A successful exploit could allow the attacker to overwrite policies and impact the configuration and operation of the affected device.
Metrics
Affected Vendors & Products
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2021-6944 | A vulnerability in an access control mechanism of Cisco Firepower Management Center (FMC) Software could allow an authenticated, remote attacker to access services beyond the scope of their authorization. This vulnerability is due to insufficient enforcement of access control in the affected software. An attacker could exploit this vulnerability by directly accessing the internal services of an affected device. A successful exploit could allow the attacker to overwrite policies and impact the configuration and operation of the affected device. |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Tue, 26 Nov 2024 16:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Cisco secure Firewall Management Center
|
|
| CPEs | cpe:2.3:a:cisco:secure_firewall_management_center:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Cisco firepower Management Center
|
Cisco secure Firewall Management Center
|
Sat, 09 Nov 2024 00:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: cisco
Published:
Updated: 2024-11-08T23:23:22.510Z
Reserved: 2020-11-13T00:00:00
Link: CVE-2021-1477
Updated: 2024-08-03T16:11:17.337Z
Status : Modified
Published: 2021-04-29T18:15:09.233
Modified: 2024-11-26T16:09:02.407
Link: CVE-2021-1477
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD