CVE-2020-3311 MEDIUM

CVE-2020-3311: Cisco Firepower Management Center Open Redirect Vulnerability

Vendor Cisco
Product Cisco Firepower Management Center
Weakness CWE-601 · Open redirect
Published May 6, 2020
Last update November 15, 2024

CVSS base score

4.3/10
Attack vector Network
Attack complexity Low
Privileges required None
User interaction Required
Confidentiality Low
Integrity None

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N

What the vulnerability does

01Description

A vulnerability in the web interface of Cisco Firepower Management Center (FMC) Software could allow an unauthenticated, remote attacker to redirect a user to a malicious web page. The vulnerability is due to improper input validation of HTTP request parameters. An attacker could exploit this vulnerability by intercepting and modifying an HTTP request from a user. A successful exploit could allow the attacker to redirect the user to a specific malicious web page.

Key dates

02Disclosure timeline

May 6, 2020 CVE published
November 15, 2024 Record updated