CVE-2023-20005 describes multiple stored cross-site scripting (XSS) vulnerabilities in the web-based management interface of Cisco Firepower Management Center (FMC) Software. An unauthenticated, remote attacker can exploit these flaws due to insufficient input validation, injecting malicious script into various data fields. This medium-severity vulnerability (CVSS 6.1) allows attackers to execute arbitrary script code in the context of the interface, access sensitive browser information, and potentially cause a temporary availability impact to parts of the FMC Dashboard. There is no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or inclusion in CISA's KEV catalog, though it has received some community and media attention.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 6.2.3, <= 6.2.3.18CPE matchmatch criteria | cpe:2.3:a:cisco:secure_firewall_management_center:*:*:*:*:*:*:*:* | ||
>= 6.4.0, <= 6.4.0.16CPE matchmatch criteria | cpe:2.3:a:cisco:secure_firewall_management_center:*:*:*:*:*:*:*:* | ||
>= 6.6.0, <= 6.6.7.1CPE matchmatch criteria | cpe:2.3:a:cisco:secure_firewall_management_center:*:*:*:*:*:*:*:* | ||
>= 7.0.0, <= 7.0.5CPE matchmatch criteria | cpe:2.3:a:cisco:secure_firewall_management_center:*:*:*:*:*:*:*:* | ||
>= 7.1.0, <= 7.1.0.3CPE matchmatch criteria | cpe:2.3:a:cisco:secure_firewall_management_center:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.