A vulnerability in the web interface of Cisco Firepower Management Center (FMC) Software could allow an unauthenticated, remote attacker to redirect a user to a malicious web page. The vulnerability is due to improper input validation of HTTP request parameters. An attacker could exploit this vulnerability by intercepting and modifying an HTTP request from a user. A successful exploit could allow the attacker to redirect the user to a specific malicious web page.
References
Link | Resource |
---|---|
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-fmc-webredirect-TcFgd42y | Vendor Advisory |
Configurations
History
No history.
Information
Published : 2020-05-06 17:15
Updated : 2020-05-12 16:02
NVD link : CVE-2020-3311
Mitre link : CVE-2020-3311
CVE.ORG link : CVE-2020-3311
JSON object : View
Products Affected
cisco
- firepower_management_center
CWE
CWE-601
URL Redirection to Untrusted Site ('Open Redirect')