Lucene search

K
cvelistCiscoCVELIST:CVE-2021-1369
HistoryApr 29, 2021 - 5:30 p.m.

CVE-2021-1369 Cisco Firepower Device Manager On-Box Software XML External Entity Vulnerability

2021-04-2917:30:22
CWE-611
cisco
www.cve.org
6
vulnerability
rest api
cisco firepower device manager
fdm on-box software
xml
xxe
remote attacker
information disclosure
denial of service
cve-2021-1369

CVSS3

5.4

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

NONE

Availability Impact

LOW

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:L

AI Score

5.9

Confidence

High

EPSS

0.001

Percentile

34.0%

A vulnerability in the REST API of Cisco Firepower Device Manager (FDM) On-Box Software could allow an authenticated, remote attacker to gain read and write access to information that is stored on an affected device. This vulnerability is due to the improper handling of XML External Entity (XXE) entries when parsing certain XML files. An attacker could exploit this vulnerability by sending malicious requests that contain references in XML entities to an affected system. A successful exploit could allow the attacker to retrieve files from the local system, resulting in the disclosure of sensitive information or causing a partial denial of service (DoS) condition on the affected device.

CNA Affected

[
  {
    "product": "Cisco Firepower Threat Defense Software",
    "vendor": "Cisco",
    "versions": [
      {
        "status": "affected",
        "version": "n/a"
      }
    ]
  }
]

CVSS3

5.4

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

NONE

Availability Impact

LOW

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:L

AI Score

5.9

Confidence

High

EPSS

0.001

Percentile

34.0%

Related for CVELIST:CVE-2021-1369