CVE-2021-34763

Multiple vulnerabilities in the web-based management interface of Cisco Firepower Management Center (FMC) Software could allow an attacker to execute a cross-site scripting (XSS) attack or an open redirect attack. For more information about these vulnerabilities, see the Details section of this advisory.
Open Redirect
Cross-site Scripting
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
4.8 MEDIUM
NETWORK
LOW
HIGH
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N
ciscoCNA
4.8 MEDIUM
NETWORK
LOW
HIGH
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N
CVEADP
---
---
CISA-ADPADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 52%
VendorProductVersion
ciscofirepower_management_center_virtual_appliance
6.1.0
ciscofirepower_management_center_virtual_appliance
6.2.0
ciscofirepower_management_center_virtual_appliance
6.2.3
ciscofirepower_management_center_virtual_appliance
6.3.0
ciscofirepower_management_center_virtual_appliance
6.4.0
ciscofirepower_management_center_virtual_appliance
6.5.0
ciscofirepower_management_center_virtual_appliance
6.6.0
ciscofirepower_management_center_virtual_appliance
6.6.1
ciscofirepower_management_center_virtual_appliance
6.7.0
ciscofirepower_management_center_virtual_appliance
7.0.0
ciscofirepower_management_center_virtual_appliance
7.1.0
ciscofirepower_threat_defense
𝑥
< 6.4.0.13
ciscofirepower_threat_defense
6.5.0 ≤
𝑥
< 6.6.5
ciscofirepower_threat_defense
6.7.0 ≤
𝑥
< 6.7.0.3
ciscosourcefire_defense_center
6.1.0
ciscosourcefire_defense_center
6.2.0
ciscosourcefire_defense_center
6.2.3
ciscosourcefire_defense_center
6.3.0
ciscosourcefire_defense_center
6.4.0
ciscosourcefire_defense_center
6.5.0
ciscosourcefire_defense_center
6.6.0
ciscosourcefire_defense_center
6.6.1
ciscosourcefire_defense_center
6.7.0
ciscosourcefire_defense_center
7.0.0
ciscosourcefire_defense_center
7.1.0
𝑥
= Vulnerable software versions