CVE-2020-3171
7.8
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Exploitability: 1.8 / Impact: 5.9
Source: NVD
Description
A vulnerability in the local management (local-mgmt) CLI of Cisco FXOS Software and Cisco UCS Manager Software could allow an authenticated, local attacker to execute arbitrary commands on the underlying operating system (OS) of an affected device. The vulnerability is due to insufficient input validation. An attacker could exploit this vulnerability by including crafted arguments to specific commands. A successful exploit could allow the attacker to execute arbitrary commands on the underlying OS with the privileges of the currently logged-in user for all affected platforms excluding Cisco UCS 6400 Series Fabric Interconnects. On Cisco UCS 6400 Series Fabric Interconnects, the injected commands are executed with root privileges.
Affected (3)
Products: Cisco: Ucs Manager, Fxos
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Version 4.0(1a)a |
| Running on/with | Platform Versions |
|---|---|
Cisco Ucs 6248up | All versions |
Cisco Ucs 6296up | All versions |
Cisco Ucs 6324 | All versions |
Cisco Ucs 6332 | All versions |
Cisco Ucs 6332 16up | All versions |
Cisco Ucs 64108 | All versions |
Cisco Ucs 6454 | All versions |
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| Version 2.4(1.214) |
| Running on/with | Platform Versions |
|---|---|
Cisco Firepower 2110 | All versions |
Cisco Firepower 2120 | All versions |
Cisco Firepower 2130 | All versions |
Cisco Firepower 2140 | All versions |
Cisco Firepower 4110 | All versions |
Cisco Firepower 4115 | All versions |
Cisco Firepower 4120 | All versions |
Cisco Firepower 4125 | All versions |
Cisco Firepower 4140 | All versions |
Cisco Firepower 4145 | All versions |
Cisco Firepower 4150 | All versions |
Cisco Firepower 9300 | All versions |
References (2)
Source: psirt@cisco.com
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Timeline
No history available yet.