← Back

CVE-2021-1448

nvd nist
Published: Apr 29, 2021Modified: Nov 21, 2024

JSON object

Loading...
7.8
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Exploitability: 1.8 / Impact: 5.9
Source: NVD

Description

A vulnerability in the CLI of Cisco Firepower Threat Defense (FTD) Software could allow an authenticated, local attacker to execute arbitrary commands with root privileges on the underlying operating system of an affected device that is running in multi-instance mode. This vulnerability is due to insufficient validation of user-supplied command arguments. An attacker could exploit this vulnerability by submitting crafted input to the affected command. A successful exploit could allow the attacker to execute commands on the underlying operating system with root privileges.

Affected (3)

1 product
Firepower Threat Defense
Configuration A
3 vulnerable · 9 platform
Vulnerable SoftwareAffected Versions
Cisco
From 6.4.0 to 6.4.0.10
From 6.5.0 to 6.5.0.5
From 6.6.0 to 6.6.1
Running on/withPlatform Versions
Cisco
Firepower 4110
All versions
Cisco
Firepower 4112
All versions
Cisco
Firepower 4115
All versions
Cisco
Firepower 4120
All versions
Cisco
Firepower 4125
All versions
Cisco
Firepower 4140
All versions
Cisco
Firepower 4145
All versions
Cisco
Firepower 4150
All versions
Cisco
Firepower 9300
All versions

Timeline

No history available yet.