CVE-2023-20155 is a denial-of-service (DoS) vulnerability in the logging API of Cisco Firepower Management Center (FMC) Software. An unauthenticated, remote attacker can exploit this by sending a high rate of HTTP requests, causing the device to become unresponsive or reload due to CPU spikes. The vulnerability also allows authenticated users without Administrator privileges to access restricted log files. Rated as MEDIUM severity with a CVSS score of 6.5, the attack vector is network-based with low attack complexity and requires low privileges for the information disclosure aspect, but no privileges for the DoS. The primary impact is high availability impact (DoS), with no impact on confidentiality or integrity. There is no evidence of active exploitation, and no public exploit code (Metasploit, Nuclei, ExploitDB) is available. Community discussion and media coverage are minimal, suggesting low current attention to this vulnerability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 6.2.3, <= 6.2.3.18CPE matchmatch criteria | cpe:2.3:a:cisco:secure_firewall_management_center:*:*:*:*:*:*:*:* | ||
>= 6.4.0, <= 6.4.0.16CPE matchmatch criteria | cpe:2.3:a:cisco:secure_firewall_management_center:*:*:*:*:*:*:*:* | ||
>= 6.6.0, <= 6.6.7.1CPE matchmatch criteria | cpe:2.3:a:cisco:secure_firewall_management_center:*:*:*:*:*:*:*:* | ||
>= 7.0.0, <= 7.0.5CPE matchmatch criteria | cpe:2.3:a:cisco:secure_firewall_management_center:*:*:*:*:*:*:*:* | ||
>= 7.1.0, <= 7.1.0.3CPE matchmatch criteria | cpe:2.3:a:cisco:secure_firewall_management_center:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.