Cisco has fixed a serious SQL injection vulnerability in its Firepower Management Center (FMC) Software .

The vulnerability is tracked as CVE-2024-20360 and is located in the web-based management interface of Cisco Firepower Management Center (FMC) Software. An attacker can exploit it to retrieve data from the database ,execute commands on the underlying operating system , and gain root privileges. However, the exploitation is only possible if the attacker has (at least) Read Only user credentials.
See also: ArcaneDoor: Hackers use Cisco zero-day to compromise networks
“A vulnerability in the web-based management interface of the Cisco Firepower Management Center (FMC) could allow an authorized, remote attacker to conduct SQL injection attacks on the affected system,” the company says. “credentials user. An attacker could exploit this vulnerability by authenticating to the application and sending crafted SQL queries to an affected system.”
Cisco recommends that system administrators apply the updates security, as there are no other solutions to address this vulnerability.
See also: Cisco discloses root escalation flaw in IMC
The vulnerability does not affect Adaptive Security Appliance (ASA) software or Firepower Threat Defense (FTD) software.

In today's digital age, businesses must prioritize cybersecurity measures to protect their data and operations. Vigilance about patching known vulnerabilities, like the one discovered by Cisco, is crucial to preventing potential breaches and ensuring the security of sensitive information.
See also: Cisco: Brute-force attacks target VPN services
By staying informed and taking timely action , organizations can better protect themselves from cyber threats . Therefore, it is essential for businesses to regularly update their software and systems with the latest security patches (e.g. for the Cisco vulnerability).
Additionally, it is important for organizations to have a comprehensive cybersecurity plan that includes regular vulnerability assessments and timely remediation processes. By prioritizing security, businesses can protect themselves from potential attacks and maintain customer trust by protecting their sensitive information.
Source: securityaffairs.com
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
