CVE-2023-20114 is a medium-severity vulnerability in the file download feature of Cisco Firepower Management Center (FMC) Software, stemming from insufficient input sanitation. An authenticated, remote attacker can exploit this by sending a crafted HTTPS request to download arbitrary files from the affected system. The CVSS score is 6.5, indicating a network-based attack with low complexity and privileges, leading to high confidentiality impact. There is currently no public exploit code available (Metasploit, Nuclei, ExploitDB), it is not listed in CISA's KEV catalog, and community discussion and media coverage are minimal.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 6.2.3, <= 6.2.3.18CPE matchmatch criteria | cpe:2.3:a:cisco:secure_firewall_management_center:*:*:*:*:*:*:*:* | ||
>= 6.4.0, <= 6.4.0.16CPE matchmatch criteria | cpe:2.3:a:cisco:secure_firewall_management_center:*:*:*:*:*:*:*:* | ||
>= 6.6.0, <= 6.6.7.1CPE matchmatch criteria | cpe:2.3:a:cisco:secure_firewall_management_center:*:*:*:*:*:*:*:* | ||
>= 7.0.0, <= 7.0.5CPE matchmatch criteria | cpe:2.3:a:cisco:secure_firewall_management_center:*:*:*:*:*:*:*:* | ||
>= 7.1.0, <= 7.1.0.3CPE matchmatch criteria | cpe:2.3:a:cisco:secure_firewall_management_center:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.