Back to search

Cisco

Secure Firewall Management Center (FMC)

See the latest tracked release, confirm when it was published, and subscribe for update emails.

Current version EOL
Last checked: 2026-09-04

7.3.1

Release date
May 09, 2024
Security status
Current version appears affected by 10 high-severity CVEs.

Source

Vendor Release Information

Public release notes are linked for the latest stored release.

Release history

See the latest published releases stored for this product.

Version Published Notes
7.3.1 2024-05-09 Release Notes

Vulnerability tracking

versionPing monitors CVEs for this product. Matching CVEs are listed below. We only display CVEs with a CVSS score of 7.0 or higher that were published within the last 90 days.

Affected status is inferred from published affected version ranges where available. Always verify against the vendor advisory before making production decisions.

CVE Severity Published Status Summary
CVE-2026-20002 HIGH (8.1) 2026-03-04 Current versionaffected

A vulnerability in the web-based management interface of Cisco Secure FMC Software could allow an authenticated, remote attacker to conduct SQL injection attacks on an affected system. This vulnerability is due to inadequate validation of user-supplied input. An attacker could exploit this vulnerability by sending crafted requests to an affected device. A successful exploit could allow the attacker to obtain full access to the database and read certain files on the underlying operating system. To exploit this vulnerability, the attacker would need valid user credentials.

Affected versions
  • 6.4.0
  • 6.4.0.1
Show 77 more
  • 6.4.0.3
  • 6.4.0.2
  • 6.4.0.4
  • 6.4.0.5
  • 6.4.0.6
  • 6.4.0.7
  • 6.4.0.8
  • 6.4.0.9
  • 6.4.0.10
  • 6.4.0.11
  • 6.4.0.12
  • 6.4.0.13
  • 6.4.0.14
  • 6.4.0.15
  • 6.4.0.16
  • 6.4.0.17
  • 6.4.0.18
  • 7.0.0
  • 7.0.0.1
  • 7.0.1
  • 7.0.1.1
  • 7.0.2
  • 7.0.2.1
  • 7.0.3
  • 7.0.4
  • 7.0.5
  • 7.0.6
  • 7.0.6.1
  • 7.0.6.2
  • 7.0.6.3
  • 7.0.7
  • 7.0.8
  • 7.0.8.1
  • 7.1.0
  • 7.1.0.1
  • 7.1.0.2
  • 7.1.0.3
  • 7.2.0
  • 7.2.1
  • 7.2.2
  • 7.2.0.1
  • 7.2.3
  • 7.2.3.1
  • 7.2.4
  • 7.2.4.1
  • 7.2.5
  • 7.2.5.1
  • 7.2.6
  • 7.2.7
  • 7.2.5.2
  • 7.2.8
  • 7.2.8.1
  • 7.2.9
  • 7.2.10
  • 7.2.10.2
  • 7.2.10.1
  • 7.3.0
  • 7.3.1
  • 7.3.1.1
  • 7.3.1.2
  • 7.4.0
  • 7.4.1
  • 7.4.1.1
  • 7.4.2
  • 7.4.2.1
  • 7.4.2.2
  • 7.4.2.3
  • 7.4.2.4
  • 7.4.3
  • 7.6.0
  • 7.6.1
  • 7.6.2
  • 7.6.2.1
  • 7.6.3
  • 7.7.0
  • 7.7.10
  • 7.7.10.1
CVE-2026-20131 CRITICAL (10.0) 2026-03-04 Current versionaffected

A vulnerability in the web-based management interface of Cisco Secure Firewall Management Center (FMC) Software could allow an unauthenticated, remote attacker to execute arbitrary Java code as root on an affected device. This vulnerability is due to insecure deserialization of a user-supplied Java byte stream. An attacker could exploit this vulnerability by sending a crafted serialized Java object to the web-based management interface of an affected device. A successful exploit could allow the attacker to execute arbitrary code on the device and elevate privileges to root. Note: If the FMC management interface does not have public internet access, the attack surface that is associated with this vulnerability is reduced.

Affected versions
  • 7.0.0
  • 7.0.0.1
Show 68 more
  • 7.0.1
  • 7.1.0
  • 6.4.0.13
  • 7.0.1.1
  • 6.4.0.14
  • 7.1.0.1
  • 7.0.2
  • 6.4.0.15
  • 7.2.0
  • 7.0.2.1
  • 7.0.3
  • 7.1.0.2
  • 7.2.0.1
  • 7.0.4
  • 7.2.1
  • 7.0.5
  • 6.4.0.16
  • 7.3.0
  • 7.2.2
  • 7.3.1
  • 7.2.3
  • 7.1.0.3
  • 7.2.3.1
  • 7.2.4
  • 7.0.6
  • 7.2.4.1
  • 7.2.5
  • 7.3.1.1
  • 7.4.0
  • 6.4.0.17
  • 7.0.6.1
  • 7.2.5.1
  • 7.4.1
  • 7.2.6
  • 7.4.1.1
  • 7.0.6.2
  • 6.4.0.18
  • 7.2.7
  • 7.2.5.2
  • 7.3.1.2
  • 7.2.8
  • 7.6.0
  • 7.4.2
  • 7.2.8.1
  • 7.0.6.3
  • 7.4.2.1
  • 7.2.9
  • 7.0.7
  • 7.7.0
  • 7.4.2.2
  • 7.2.10
  • 7.6.1
  • 7.4.2.3
  • 7.0.8
  • 7.6.2
  • 7.7.10
  • 7.2.10.1
  • 7.0.8.1
  • 7.6.2.1
  • 7.2.10.2
  • 7.7.10.1
  • 7.4.2.4
  • 7.4.3
  • 7.7.11
  • 7.6.4
  • 10.0.0
  • 7.4.4
  • 7.4.5
CVE-2026-20079 CRITICAL (10.0) 2026-03-04 Current versionaffected

A vulnerability in the web interface of Cisco Secure Firewall Management Center (FMC) Software could allow an unauthenticated, remote attacker to bypass authentication and execute script files on an affected device to obtain root access to the underlying operating system.  This vulnerability is due to an improper system process that is created at boot time. An attacker could exploit this vulnerability by sending crafted HTTP requests to an affected device. A successful exploit could allow the attacker to execute a variety of scripts and commands that allow root access to the device. 

Affected versions
  • 7.0.0
  • 7.0.0.1
Show 69 more
  • 7.0.1
  • 7.1.0
  • 7.0.1.1
  • 7.1.0.1
  • 7.0.2
  • 7.2.0
  • 7.0.2.1
  • 7.0.3
  • 7.1.0.2
  • 7.2.0.1
  • 7.0.4
  • 7.2.1
  • 7.0.5
  • 7.3.0
  • 7.2.2
  • 7.3.1
  • 7.2.3
  • 7.1.0.3
  • 7.2.3.1
  • 7.2.4
  • 7.0.6
  • 7.2.4.1
  • 7.2.5
  • 7.3.1.1
  • 7.4.0
  • 7.0.6.1
  • 7.2.5.1
  • 7.4.1
  • 7.2.6
  • 7.4.1.1
  • 7.0.6.2
  • 7.2.7
  • 7.2.5.2
  • 7.3.1.2
  • 7.2.8
  • 7.6.0
  • 7.4.2
  • 7.2.8.1
  • 7.0.6.3
  • 7.4.2.1
  • 7.2.9
  • 7.0.7
  • 7.7.0
  • 7.4.2.2
  • 7.2.10
  • 7.6.1
  • 7.4.2.3
  • 7.0.8
  • 7.6.2
  • 7.7.10
  • 7.2.10.1
  • 7.0.8.1
  • 7.6.2.1
  • 7.2.10.2
  • 7.7.10.1
  • 7.4.2.4
  • 7.4.3
  • 7.7.11
  • 7.6.4
  • 10.0.0
  • 7.4.4
  • 7.4.5
  • 7.0.9
  • 7.2.11
  • 7.7.12
  • 7.6.5
  • 7.4.6
  • 10.0.1
  • 7.4.7
CVE-2024-20424 CRITICAL (9.9) 2024-10-23 Current versionaffected

A vulnerability in the web-based management interface of Cisco Secure Firewall Management Center (FMC) Software, formerly Firepower Management Center Software, could allow an authenticated, remote attacker to execute arbitrary commands on the underlying operating system as root. This vulnerability is due to insufficient input validation of certain HTTP requests. An attacker could exploit this vulnerability by authenticating to the web-based management interface of an affected device and then sending a crafted HTTP request to the device. A successful exploit could allow the attacker to execute arbitrary commands with root permissions on the underlying operating system of the Cisco FMC device or to execute commands on managed Cisco Firepower Threat Defense (FTD) devices. To exploit this vulnerability, the attacker would need valid credentials for a user account with at least the role of Security Analyst (Read Only).

Affected versions
  • 6.2.3
  • 6.2.3.1
Show 90 more
  • 6.2.3.2
  • 6.2.3.3
  • 6.2.3.4
  • 6.2.3.5
  • 6.2.3.6
  • 6.2.3.7
  • 6.2.3.9
  • 6.2.3.10
  • 6.2.3.11
  • 6.2.3.12
  • 6.2.3.13
  • 6.2.3.14
  • 6.2.3.15
  • 6.2.3.8
  • 6.2.3.16
  • 6.2.3.17
  • 6.2.3.18
  • 6.4.0
  • 6.4.0.1
  • 6.4.0.3
  • 6.4.0.2
  • 6.4.0.4
  • 6.4.0.5
  • 6.4.0.6
  • 6.4.0.7
  • 6.4.0.8
  • 6.4.0.9
  • 6.4.0.10
  • 6.4.0.11
  • 6.4.0.12
  • 6.4.0.13
  • 6.4.0.14
  • 6.4.0.15
  • 6.4.0.16
  • 6.4.0.17
  • 6.4.0.18
  • 6.6.0
  • 6.6.0.1
  • 6.6.1
  • 6.6.3
  • 6.6.4
  • 6.6.5
  • 6.6.5.1
  • 6.6.5.2
  • 6.6.7
  • 6.6.7.1
  • 6.6.7.2
  • 6.7.0
  • 6.7.0.1
  • 6.7.0.2
  • 6.7.0.3
  • 7.0.0
  • 7.0.0.1
  • 7.0.1
  • 7.0.1.1
  • 7.0.2
  • 7.0.2.1
  • 7.0.3
  • 7.0.4
  • 7.0.5
  • 7.0.6
  • 7.0.6.1
  • 7.0.6.2
  • 7.1.0
  • 7.1.0.1
  • 7.1.0.2
  • 7.1.0.3
  • 7.2.0
  • 7.2.1
  • 7.2.2
  • 7.2.0.1
  • 7.2.3
  • 7.2.3.1
  • 7.2.4
  • 7.2.4.1
  • 7.2.5
  • 7.2.5.1
  • 7.2.6
  • 7.2.7
  • 7.2.5.2
  • 7.2.8
  • 7.2.8.1
  • 7.3.0
  • 7.3.1
  • 7.3.1.1
  • 7.3.1.2
  • 7.4.0
  • 7.4.1
  • 7.4.1.1
  • 7.4.2
CVE-2024-20360 HIGH (8.8) 2024-05-22 Current versionaffected

A vulnerability in the web-based management interface of Cisco Firepower Management Center (FMC) Software could allow an authenticated, remote attacker to conduct SQL injection attacks on an affected system. This vulnerability exists because the web-based management interface does not adequately validate user input. An attacker could exploit this vulnerability by authenticating to the application and sending crafted SQL queries to an affected system. A successful exploit could allow the attacker to obtain any data from the database, execute arbitrary commands on the underlying operating system, and elevate privileges to root. To exploit this vulnerability, an attacker would need at least Read Only user credentials.

Affected versions
  • 7.0.0
  • 7.0.0.1
Show 25 more
  • 7.0.1
  • 7.0.1.1
  • 7.0.2
  • 7.0.2.1
  • 7.0.3
  • 7.0.4
  • 7.0.5
  • 7.0.6
  • 7.1.0
  • 7.1.0.1
  • 7.1.0.2
  • 7.1.0.3
  • 7.2.0
  • 7.2.1
  • 7.2.2
  • 7.2.0.1
  • 7.2.3
  • 7.2.3.1
  • 7.2.4
  • 7.2.4.1
  • 7.2.5
  • 7.3.0
  • 7.3.1
  • 7.3.1.1
  • 7.3.1.2
CVE-2023-20063 HIGH (8.2) 2023-11-01 Current versionaffected

A vulnerability in the inter-device communication mechanisms between devices that are running Cisco Firepower Threat Defense (FTD) Software and devices that are running Cisco Firepower Management (FMC) Software could allow an authenticated, local attacker to execute arbitrary commands with root permissions on the underlying operating system of an affected device. This vulnerability is due to insufficient validation of user-supplied input. An attacker could exploit this vulnerability by accessing the expert mode of an affected device and submitting specific commands to a connected system. A successful exploit could allow the attacker to execute arbitrary code in the context of an FMC device if the attacker has administrative privileges on an associated FTD device. Alternatively, a successful exploit could allow the attacker to execute arbitrary code in the context of an FTD device if the attacker has administrative privileges on an associated FMC device.

Affected versions
  • 6.2.3.12
  • 6.2.3.1
Show 89 more
  • 6.2.3.10
  • 6.2.3.8
  • 6.4.0.6
  • 6.2.3
  • 6.4.0.7
  • 6.2.3.13
  • 6.2.3.5
  • 6.4.0.4
  • 6.2.3.9
  • 6.2.3.14
  • 6.4.0.1
  • 6.2.3.6
  • 6.2.3.11
  • 6.4.0.8
  • 6.2.3.2
  • 6.4.0.2
  • 6.2.3.3
  • 6.4.0.3
  • 6.2.3.7
  • 6.2.3.4
  • 6.4.0.5
  • 6.4.0
  • 6.2.3.15
  • 6.6.0
  • 6.4.0.9
  • 6.2.3.16
  • 6.6.0.1
  • 6.6.1
  • 6.4.0.10
  • 6.7.0
  • 6.4.0.11
  • 6.6.3
  • 6.7.0.1
  • 6.6.4
  • 6.4.0.12
  • 6.7.0.2
  • 7.0.0
  • 6.2.3.17
  • 7.0.0.1
  • 6.6.5
  • 7.0.1
  • 7.1.0
  • 6.6.5.1
  • 6.4.0.13
  • 6.7.0.3
  • 7.0.1.1
  • 6.2.3.18
  • 6.4.0.14
  • 6.6.5.2
  • 7.1.0.1
  • 7.0.2
  • 6.4.0.15
  • 7.2.0
  • 7.0.2.1
  • 7.0.3
  • 6.6.7
  • 7.1.0.2
  • 7.2.0.1
  • 7.0.4
  • 7.2.1
  • 7.0.5
  • 6.4.0.16
  • 7.3.0
  • 7.2.2
  • 6.6.7.1
  • 7.3.1
  • 7.2.3
  • 7.1.0.3
  • 7.2.3.1
  • 7.2.4
  • 7.0.6
  • 7.2.4.1
  • 7.2.5
  • 7.3.1.1
  • 7.4.0
  • 6.4.0.17
  • 7.0.6.1
  • 7.2.5.1
  • 7.4.1
  • 7.2.6
  • 7.4.1.1
  • 7.0.6.2
  • 6.4.0.18
  • 6.6.7.2
  • 7.2.7
  • 7.2.5.2
  • 7.3.1.2
  • 7.2.8
  • 7.2.8.1
CVE-2023-20220 HIGH (7.2) 2023-11-01 Current versionaffected

Multiple vulnerabilities in the web-based management interface of Cisco Firepower Management Center (FMC) Software could allow an authenticated, remote attacker to execute arbitrary commands on the underlying operating system. To exploit these vulnerabilities, the attacker must have valid device credentials, but does not need Administrator privileges. These vulnerabilities are due to insufficient validation of user-supplied input for certain configuration options. An attacker could exploit these vulnerabilities by using crafted input within the device configuration GUI. A successful exploit could allow the attacker to execute arbitrary commands on the device, including on the underlying operating system, which could also affect the availability of the device.

Affected versions
  • 6.2.3
  • 6.2.3.1
Show 72 more
  • 6.2.3.2
  • 6.2.3.3
  • 6.2.3.4
  • 6.2.3.5
  • 6.2.3.6
  • 6.2.3.7
  • 6.2.3.9
  • 6.2.3.10
  • 6.2.3.11
  • 6.2.3.12
  • 6.2.3.13
  • 6.2.3.14
  • 6.2.3.15
  • 6.2.3.8
  • 6.2.3.16
  • 6.2.3.17
  • 6.2.3.18
  • 6.4.0
  • 6.4.0.1
  • 6.4.0.3
  • 6.4.0.2
  • 6.4.0.4
  • 6.4.0.5
  • 6.4.0.6
  • 6.4.0.7
  • 6.4.0.8
  • 6.4.0.9
  • 6.4.0.10
  • 6.4.0.11
  • 6.4.0.12
  • 6.4.0.13
  • 6.4.0.14
  • 6.4.0.15
  • 6.4.0.16
  • 6.6.0
  • 6.6.0.1
  • 6.6.1
  • 6.6.3
  • 6.6.4
  • 6.6.5
  • 6.6.5.1
  • 6.6.5.2
  • 6.6.7
  • 6.6.7.1
  • 6.7.0
  • 6.7.0.1
  • 6.7.0.2
  • 6.7.0.3
  • 7.0.0
  • 7.0.0.1
  • 7.0.1
  • 7.0.1.1
  • 7.0.2
  • 7.0.2.1
  • 7.0.3
  • 7.0.4
  • 7.0.5
  • 7.1.0
  • 7.1.0.1
  • 7.1.0.2
  • 7.1.0.3
  • 7.2.0
  • 7.2.1
  • 7.2.2
  • 7.2.0.1
  • 7.2.3
  • 7.2.3.1
  • 7.2.4
  • 7.3.0
  • 7.3.1
  • 7.3.1.1
  • 6.2..12
CVE-2023-20219 HIGH (7.2) 2023-11-01 Current versionaffected

Multiple vulnerabilities in the web management interface of Cisco Firepower Management Center (FMC) Software could allow an authenticated, remote attacker to execute arbitrary commands on the underlying operating system. The attacker would need valid device credentials but does not require administrator privileges to exploit this vulnerability. These vulnerabilities are due to insufficient validation of user-supplied input for certain configuration options. An attacker could exploit these vulnerabilities by using crafted input within the device configuration GUI. A successful exploit could allow the attacker to execute arbitrary commands on the device including the underlying operating system which could also affect the availability of the device.

Affected versions
  • 6.7.0
  • 6.7.0.1
Show 26 more
  • 6.7.0.2
  • 6.7.0.3
  • 7.0.0
  • 7.0.0.1
  • 7.0.1
  • 7.0.1.1
  • 7.0.2
  • 7.0.2.1
  • 7.0.3
  • 7.0.4
  • 7.0.5
  • 7.1.0
  • 7.1.0.1
  • 7.1.0.2
  • 7.1.0.3
  • 7.2.0
  • 7.2.1
  • 7.2.2
  • 7.2.0.1
  • 7.2.3
  • 7.2.3.1
  • 7.2.4
  • 7.3.0
  • 7.3.1
  • 7.3.1.1
  • 7.3.1.2
CVE-2023-20048 CRITICAL (9.9) 2023-11-01 Current versionaffected

A vulnerability in the web services interface of Cisco Firepower Management Center (FMC) Software could allow an authenticated, remote attacker to execute certain unauthorized configuration commands on a Firepower Threat Defense (FTD) device that is managed by the FMC Software. This vulnerability is due to insufficient authorization of configuration commands that are sent through the web service interface. An attacker could exploit this vulnerability by authenticating to the FMC web services interface and sending a crafted HTTP request to an affected device. A successful exploit could allow the attacker to execute certain configuration commands on the targeted FTD device. To successfully exploit this vulnerability, an attacker would need valid credentials on the FMC Software.

Affected versions
  • 6.2.3
  • 6.2.3.1
Show 70 more
  • 6.2.3.2
  • 6.2.3.3
  • 6.2.3.4
  • 6.2.3.5
  • 6.2.3.6
  • 6.2.3.7
  • 6.2.3.9
  • 6.2.3.10
  • 6.2.3.11
  • 6.2.3.12
  • 6.2.3.13
  • 6.2.3.14
  • 6.2.3.15
  • 6.2.3.8
  • 6.2.3.16
  • 6.2.3.17
  • 6.2.3.18
  • 6.4.0
  • 6.4.0.1
  • 6.4.0.3
  • 6.4.0.2
  • 6.4.0.4
  • 6.4.0.5
  • 6.4.0.6
  • 6.4.0.7
  • 6.4.0.8
  • 6.4.0.9
  • 6.4.0.10
  • 6.4.0.11
  • 6.4.0.12
  • 6.4.0.13
  • 6.4.0.14
  • 6.4.0.15
  • 6.4.0.16
  • 6.6.0
  • 6.6.0.1
  • 6.6.1
  • 6.6.3
  • 6.6.4
  • 6.6.5
  • 6.6.5.1
  • 6.6.5.2
  • 6.6.7
  • 6.6.7.1
  • 6.7.0
  • 6.7.0.1
  • 6.7.0.2
  • 6.7.0.3
  • 7.0.0
  • 7.0.0.1
  • 7.0.1
  • 7.0.1.1
  • 7.0.2
  • 7.0.2.1
  • 7.0.3
  • 7.0.4
  • 7.0.5
  • 7.1.0
  • 7.1.0.1
  • 7.1.0.2
  • 7.1.0.3
  • 7.2.0
  • 7.2.1
  • 7.2.2
  • 7.2.0.1
  • 7.2.3
  • 7.2.3.1
  • 7.3.0
  • 7.3.1
  • 7.3.1.1
CVE-2023-20155 HIGH (7.5) 2023-11-01 Current versionaffected

A vulnerability in a logging API in Cisco Firepower Management Center (FMC) Software could allow an unauthenticated, remote attacker to cause the device to become unresponsive or trigger an unexpected reload. This vulnerability could also allow an attacker with valid user credentials, but not Administrator privileges, to view a system log file that they would not normally have access to. This vulnerability is due to a lack of rate-limiting of requests that are sent to a specific API that is related to an FMC log. An attacker could exploit this vulnerability by sending a high rate of HTTP requests to the API. A successful exploit could allow the attacker to cause a denial of service (DoS) condition due to the FMC CPU spiking to 100 percent utilization or to the device reloading. CPU utilization would return to normal if the attack traffic was stopped before an unexpected reload was triggered.

Affected versions
  • 6.2.3
  • 6.2.3.1
Show 70 more
  • 6.2.3.2
  • 6.2.3.3
  • 6.2.3.4
  • 6.2.3.5
  • 6.2.3.6
  • 6.2.3.7
  • 6.2.3.9
  • 6.2.3.10
  • 6.2.3.11
  • 6.2.3.12
  • 6.2.3.13
  • 6.2.3.14
  • 6.2.3.15
  • 6.2.3.8
  • 6.2.3.16
  • 6.2.3.17
  • 6.2.3.18
  • 6.4.0
  • 6.4.0.1
  • 6.4.0.3
  • 6.4.0.2
  • 6.4.0.4
  • 6.4.0.5
  • 6.4.0.6
  • 6.4.0.7
  • 6.4.0.8
  • 6.4.0.9
  • 6.4.0.10
  • 6.4.0.11
  • 6.4.0.12
  • 6.4.0.13
  • 6.4.0.14
  • 6.4.0.15
  • 6.4.0.16
  • 6.6.0
  • 6.6.0.1
  • 6.6.1
  • 6.6.3
  • 6.6.4
  • 6.6.5
  • 6.6.5.1
  • 6.6.5.2
  • 6.6.7
  • 6.6.7.1
  • 6.7.0
  • 6.7.0.1
  • 6.7.0.2
  • 6.7.0.3
  • 7.0.0
  • 7.0.0.1
  • 7.0.1
  • 7.0.1.1
  • 7.0.2
  • 7.0.2.1
  • 7.0.3
  • 7.0.4
  • 7.0.5
  • 7.1.0
  • 7.1.0.1
  • 7.1.0.2
  • 7.1.0.3
  • 7.2.0
  • 7.2.1
  • 7.2.2
  • 7.2.0.1
  • 7.2.3
  • 7.2.3.1
  • 7.3.0
  • 7.3.1
  • 7.3.1.1