CVE-2022-20941 is a medium-severity vulnerability affecting Cisco Firepower Management Center (FMC) Software, allowing an unauthenticated, remote attacker to access sensitive information. This is due to missing authorization and insufficient entropy in resource names within the web-based management interface. While the vulnerability could lead to sensitive data exposure, there is currently no evidence of active exploitation, public exploit code, or significant community discussion.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
6.1.0CPE matchmatch criteria | cpe:2.3:a:cisco:secure_firewall_management_center:6.1.0:*:*:*:*:*:*:* | ||
6.1.0.1CPE matchmatch criteria | cpe:2.3:a:cisco:secure_firewall_management_center:6.1.0.1:*:*:*:*:*:*:* | ||
6.1.0.2CPE matchmatch criteria | cpe:2.3:a:cisco:secure_firewall_management_center:6.1.0.2:*:*:*:*:*:*:* | ||
6.1.0.3CPE matchmatch criteria | cpe:2.3:a:cisco:secure_firewall_management_center:6.1.0.3:*:*:*:*:*:*:* | ||
6.1.0.4CPE matchmatch criteria | cpe:2.3:a:cisco:secure_firewall_management_center:6.1.0.4:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.