CVE-2020-3456

A vulnerability in the Cisco Firepower Chassis Manager (FCM) of Cisco FXOS Software could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack against a user of an affected device. The vulnerability is due to insufficient CSRF protections for the FCM interface. An attacker could exploit this vulnerability by persuading a targeted user to click a malicious link. A successful exploit could allow the attacker to send arbitrary requests that could take unauthorized actions on behalf of the targeted user.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:cisco:firepower_extensible_operating_system:2.4\(1.249\):*:*:*:*:*:*:*
OR cpe:2.3:h:cisco:firepower_4110:-:*:*:*:*:*:*:*
cpe:2.3:h:cisco:firepower_4112:-:*:*:*:*:*:*:*
cpe:2.3:h:cisco:firepower_4115:-:*:*:*:*:*:*:*
cpe:2.3:h:cisco:firepower_4120:-:*:*:*:*:*:*:*
cpe:2.3:h:cisco:firepower_4125:-:*:*:*:*:*:*:*
cpe:2.3:h:cisco:firepower_4140:-:*:*:*:*:*:*:*
cpe:2.3:h:cisco:firepower_4145:-:*:*:*:*:*:*:*
cpe:2.3:h:cisco:firepower_4150:-:*:*:*:*:*:*:*
cpe:2.3:h:cisco:firepower_9300_sm-24:-:*:*:*:*:*:*:*
cpe:2.3:h:cisco:firepower_9300_sm-36:-:*:*:*:*:*:*:*
cpe:2.3:h:cisco:firepower_9300_sm-40:-:*:*:*:*:*:*:*
cpe:2.3:h:cisco:firepower_9300_sm-44:-:*:*:*:*:*:*:*
cpe:2.3:h:cisco:firepower_9300_sm-44_x_3:-:*:*:*:*:*:*:*
cpe:2.3:h:cisco:firepower_9300_sm-48:-:*:*:*:*:*:*:*
cpe:2.3:h:cisco:firepower_9300_sm-56:-:*:*:*:*:*:*:*
cpe:2.3:h:cisco:firepower_9300_sm-56_x_3:-:*:*:*:*:*:*:*

History

No history.

Information

Published : 2020-10-21 19:15

Updated : 2023-12-10 13:41


NVD link : CVE-2020-3456

Mitre link : CVE-2020-3456

CVE.ORG link : CVE-2020-3456


JSON object : View

Products Affected

cisco

  • firepower_4112
  • firepower_extensible_operating_system
  • firepower_4145
  • firepower_4125
  • firepower_9300_sm-24
  • firepower_9300_sm-44_x_3
  • firepower_4120
  • firepower_9300_sm-40
  • firepower_9300_sm-36
  • firepower_9300_sm-48
  • firepower_4110
  • firepower_9300_sm-56
  • firepower_9300_sm-56_x_3
  • firepower_9300_sm-44
  • firepower_4150
  • firepower_4115
  • firepower_4140
CWE
CWE-352

Cross-Site Request Forgery (CSRF)