Lucene search

K
cvelistCiscoCVELIST:CVE-2021-1267
HistoryJan 13, 2021 - 9:45 p.m.

CVE-2021-1267 Cisco Firepower Management Center XML Entity Expansion Vulnerability

2021-01-1321:45:49
CWE-776
cisco
www.cve.org
6
cisco
firepower management center
xml entity expansion
vulnerability
denial of service
authenticated
remote attacker
memory utilization
cpu utilization

CVSS3

4.3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

LOW

CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L

AI Score

5

Confidence

High

EPSS

0.001

Percentile

40.9%

A vulnerability in the dashboard widget of Cisco Firepower Management Center (FMC) Software could allow an authenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. The vulnerability is due to improper restrictions on XML entities. An attacker could exploit this vulnerability by crafting an XML-based widget on an affected server. A successful exploit could cause increased memory and CPU utilization, which could result in a DoS condition.

CNA Affected

[
  {
    "product": "Cisco Firepower Management Center",
    "vendor": "Cisco",
    "versions": [
      {
        "status": "affected",
        "version": "n/a"
      }
    ]
  }
]

CVSS3

4.3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

LOW

CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L

AI Score

5

Confidence

High

EPSS

0.001

Percentile

40.9%

Related for CVELIST:CVE-2021-1267