CVE-2024-20388
Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
23/10/2024
Last modified:
26/11/2024
Description
A vulnerability in the password change feature of Cisco Firepower Management Center (FMC) software could allow an unauthenticated, remote attacker to determine valid user names on an affected device.<br />
<br />
This vulnerability is due to improper authentication of password update responses. An attacker could exploit this vulnerability by forcing a password reset on an affected device. A successful exploit could allow the attacker to determine valid user names in the unauthenticated response to a forced password reset.
Impact
Base Score 3.x
5.30
Severity 3.x
MEDIUM
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:cisco:firepower_management_center:6.4.0.17:*:*:*:*:*:*:* | ||
| cpe:2.3:a:cisco:firepower_management_center:6.4.0.18:*:*:*:*:*:*:* | ||
| cpe:2.3:a:cisco:firepower_management_center:6.6.7.2:*:*:*:*:*:*:* | ||
| cpe:2.3:a:cisco:firepower_management_center:7.0.6.1:*:*:*:*:*:*:* | ||
| cpe:2.3:a:cisco:firepower_management_center:7.0.6.2:*:*:*:*:*:*:* | ||
| cpe:2.3:a:cisco:firepower_management_center:7.2.5.1:*:*:*:*:*:*:* | ||
| cpe:2.3:a:cisco:firepower_management_center:7.2.5.2:*:*:*:*:*:*:* | ||
| cpe:2.3:a:cisco:firepower_management_center:7.2.6:*:*:*:*:*:*:* | ||
| cpe:2.3:a:cisco:firepower_management_center:7.2.7:*:*:*:*:*:*:* | ||
| cpe:2.3:a:cisco:firepower_management_center:7.2.8:*:*:*:*:*:*:* | ||
| cpe:2.3:a:cisco:firepower_management_center:7.2.8.1:*:*:*:*:*:*:* | ||
| cpe:2.3:a:cisco:firepower_management_center:7.4.0:*:*:*:*:*:*:* | ||
| cpe:2.3:a:cisco:firepower_management_center:7.4.1:*:*:*:*:*:*:* | ||
| cpe:2.3:a:cisco:firepower_management_center:7.4.1.1:*:*:*:*:*:*:* | ||
| cpe:2.3:a:cisco:secure_firewall_management_center:6.2.3:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page



