Vulnslist

Cisco vulnerabilities by product, model, software, and advisory.

Cisco FXOS Software and Firepower Threat Defense Software Command Injection Vulnerabilities

cisco-sa-20191002-fxos-cmd-inject · High · Published · Updated

Multiple vulnerabilities in the CLI of Cisco FXOS Software and Cisco Firepower Threat Defense (FTD) Software could allow an authenticated, local attacker to execute commands on the underlying operating system (OS) with root privileges. These vulnerabilities are due to insufficient input validation. An attacker could exploit these vulnerabilities by including crafted arguments to specific CLI commands. A successful exploit could allow the attacker to execute commands on the underlying OS with root privileges. Cisco has released software updates that address these vulnerabilities. There are no workarounds that address these vulnerabilities. This advisory is available at the following link: https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20191002-fxos-cmd-inject

Cisco advisory · CSAF JSON

Workarounds

There are no workarounds that address these vulnerabilities.

CVEsCVE-2019-12699
Cisco Bug IDsCSCvm25894, CSCvo42621, CSCvo42651, CSCvo83496, CSCvm14277, CSCvm25813, CSCvm14279
CVSS ScoreBase 8.8
Base 8.8 CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H/E:X/RL:X/RC:X
Product Names From Source
Cisco Firepower Threat Defense Software for Firepower 1000/2100 Series, Cisco Firepower Extensible Operating System (FXOS) 2.0.1.68, Cisco Firepower Extensible Operating System (FXOS) 2.0.1.201, Cisco Firepower Extensible Operating System (FXOS) 2.0.1.86, Cisco Firepower Extensible Operating System (FXOS) 2.0.1.37, Cisco Firepower Extensible Operating System (FXOS) 2.0.1.135, Cisco Firepower Extensible Operating System (FXOS) 2.0.1.141, Cisco Firepower Extensible Operating System (FXOS) 2.0.1.144, Cisco Firepower Extensible Operating System (FXOS) 2.0.1.148, Cisco Firepower Extensible Operating System (FXOS) 2.0.1.149, Cisco Firepower Extensible Operating System (FXOS) 2.0.1.153, Cisco Firepower Extensible Operating System (FXOS) 2.0.1.159, Cisco Firepower Extensible Operating System (FXOS) 2.0.1.188, Cisco Firepower Extensible Operating System (FXOS) 2.0.1.203, Cisco Firepower Extensible Operating System (FXOS) 2.0.1.204, Cisco Firepower Extensible Operating System (FXOS) 2.1.1.64, Cisco Firepower Extensible Operating System (FXOS) 2.1.1.73, Cisco Firepower Extensible Operating System (FXOS) 2.1.1.77, Cisco Firepower Extensible Operating System (FXOS) 2.1.1.83, Cisco Firepower Extensible Operating System (FXOS) 2.1.1.85, Cisco Firepower Extensible Operating System (FXOS) 2.1.1.86, Cisco Firepower Extensible Operating System (FXOS) 2.1.1.97, Cisco Firepower Extensible Operating System (FXOS) 2.1.1.106, Cisco Firepower Extensible Operating System (FXOS) 2.1.1.107, Cisco Firepower Extensible Operating System (FXOS) 2.1.1.113, Cisco Firepower Extensible Operating System (FXOS) 2.1.1.115, Cisco Firepower Extensible Operating System (FXOS) 2.1.1.116, Cisco Firepower Extensible Operating System (FXOS) 1.1.1.147, Cisco Firepower Extensible Operating System (FXOS) 1.1.1.160, Cisco Firepower Extensible Operating System (FXOS) 1.1.2.51, Cisco Firepower Extensible Operating System (FXOS) 1.1.2.178, Cisco Firepower Extensible Operating System (FXOS) 1.1.3.84, Cisco Firepower Extensible Operating System (FXOS) 1.1.3.86, Cisco Firepower Extensible Operating System (FXOS) 1.1.3.97, Cisco Firepower Extensible Operating System (FXOS) 1.1.4.95, Cisco Firepower Extensible Operating System (FXOS) 1.1.4.117, Cisco Firepower Extensible Operating System (FXOS) 1.1.4.169, Cisco Firepower Extensible Operating System (FXOS) 1.1.4.175, Cisco Firepower Extensible Operating System (FXOS) 1.1.4.178, Cisco Firepower Extensible Operating System (FXOS) 1.1.4.179, Cisco Firepower Extensible Operating System (FXOS) 2.2.1.63, Cisco Firepower Extensible Operating System (FXOS) 2.2.1.66, Cisco Firepower Extensible Operating System (FXOS) 2.2.1.70, Cisco Firepower Extensible Operating System (FXOS) 2.2.2.17, Cisco Firepower Extensible Operating System (FXOS) 2.2.2.19, Cisco Firepower Extensible Operating System (FXOS) 2.2.2.24, Cisco Firepower Extensible Operating System (FXOS) 2.2.2.26, Cisco Firepower Extensible Operating System (FXOS) 2.2.2.28, Cisco Firepower Extensible Operating System (FXOS) 2.2.2.54, Cisco Firepower Extensible Operating System (FXOS) 2.2.2.60, Cisco Firepower Extensible Operating System (FXOS) 2.2.2.71, Cisco Firepower Extensible Operating System (FXOS) 2.2.2.83, Cisco Firepower Extensible Operating System (FXOS) 2.2.2.86, Cisco Firepower Extensible Operating System (FXOS) 2.3.1.99, Cisco Firepower Extensible Operating System (FXOS) 2.3.1.93, Cisco Firepower Extensible Operating System (FXOS) 2.3.1.91, Cisco Firepower Extensible Operating System (FXOS) 2.3.1.88, Cisco Firepower Extensible Operating System (FXOS) 2.3.1.75, Cisco Firepower Extensible Operating System (FXOS) 2.3.1.73, Cisco Firepower Extensible Operating System (FXOS) 2.3.1.66, Cisco Firepower Extensible Operating System (FXOS) 2.3.1.58, Cisco Firepower Extensible Operating System (FXOS) 2.3.1.111, Cisco Firepower Extensible Operating System (FXOS) 2.3.1.110, Cisco Firepower Extensible Operating System (FXOS)

Related Products

Product CVE Evidence
Firepower Extensible Operating System CVE-2019-12699 Cisco OpenVuln
Cisco Firepower Threat Defense Software for Firepower 1000/2100 Series CVE-2019-12699 Cisco OpenVuln
Cisco Firepower Threat Defense Software CVE-2019-12699 Cisco OpenVuln
Cisco Firepower Extensible Operating System (FXOS) CVE-2019-12699 Cisco OpenVuln
Cisco Firepower Extensible Operating System CVE-2019-12699 Cisco OpenVuln