← Back

CVE-2019-12699

nvd nist
Published: Oct 2, 2019Modified: Nov 21, 2024

JSON object

Loading...
7.8
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Exploitability: 1.8 / Impact: 5.9
Source: NVD

Description

Multiple vulnerabilities in the CLI of Cisco FXOS Software and Cisco Firepower Threat Defense (FTD) Software could allow an authenticated, local attacker to execute commands on the underlying operating system (OS) with root privileges. These vulnerabilities are due to insufficient input validation. An attacker could exploit these vulnerabilities by including crafted arguments to specific CLI commands. A successful exploit could allow the attacker to execute commands on the underlying OS with root privileges.

Affected (10)

3 products
Firepower 9300 Firmware
Firepower Threat Defense
Configuration A
4 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Cisco
Version 2.4(1.214)
Version 2.4(1.216)
Version 2.4(2.54)
Version r241
Running on/withPlatform Versions
Cisco
Firepower 9300
All versions
Configuration B
3 vulnerable · 2 platform
Vulnerable SoftwareAffected Versions
Cisco
Up to 6.1.0
From 6.2.0 to 6.2.3.14
From 6.3.0 to 6.3.0.3
Running on/withPlatform Versions
Cisco
Firepower 1000
All versions
Cisco
Firepower 2100
All versions
Configuration C
3 vulnerable · 2 platform
Vulnerable SoftwareAffected Versions
Cisco
From 2.0 to 2.2.2.101
From 2.3 to 2.3.1.155
From 2.4 to 2.4.1.238
Running on/withPlatform Versions
Cisco
Firepower 4100
All versions
Cisco
Firepower 9300
All versions

Timeline

No history available yet.