PT-2019-3131 · Cisco · Cisco Firepower Management Center

·

CVE-2019-1949

·

Published

2019-08-07

·

Updated

2024-11-26

CVSS v2.0

5.5

Medium

VectorAV:N/AC:L/Au:S/C:P/I:P/A:N
Name of the Vulnerable Software and Affected Versions Cisco Firepower Management Center (affected versions not specified)
Description The issue is related to insufficient validation of user-supplied input in the web-based management interface, which could allow a remote attacker to conduct a cross-site scripting (XSS) attack. This can be achieved by persuading a user to click a malicious link, potentially allowing the attacker to execute arbitrary script code or access sensitive browser-based information.
Recommendations For Cisco Firepower Management Center, consider restricting access to the web-based management interface until a fix is available. As a temporary workaround, avoid using links from untrusted sources to minimize the risk of exploitation. Restrict access to sensitive information and ensure that users of the web-based management interface are aware of the potential risks associated with clicking on links from unknown sources.

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2019-03116
CVE-2019-1949

Affected Products

Cisco Firepower Management Center