Vulnslist

find the latest Cisco vulnerabilities

Cisco FXOS Software Buffer Overflow Vulnerability

cisco-sa-fxos-buffer-cSdmfWUt · Medium · Published · Updated

A vulnerability in Cisco FXOS Software could allow an authenticated, local attacker with administrative credentials to cause a buffer overflow condition. The vulnerability is due to incorrect bounds checking of values that are parsed from a specific file. An attacker could exploit this vulnerability by supplying a crafted file that, when it is processed, may cause a stack-based buffer overflow. A successful exploit could allow the attacker to execute arbitrary code on the underlying operating system with root privileges. An attacker would need to have valid administrative credentials to exploit this vulnerability. Cisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability. This advisory is available at the following link:https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-fxos-buffer-cSdmfWUt

Cisco advisory · CSAF JSON

Workarounds

There are no workarounds that address this vulnerability.

CVEsCVE-2020-3545
Cisco Bug IDsCSCvd72523
CVSS ScoreBase 6.0
Base 6.0 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N/E:X/RL:X/RC:X
Product Names From Source
Cisco Firepower Extensible Operating System (FXOS) 2.2.1.63, Cisco Firepower Extensible Operating System (FXOS) 2.2.1.66, Cisco Firepower Extensible Operating System (FXOS) 2.2.1.70, Cisco Firepower Extensible Operating System (FXOS) 2.2.2.17, Cisco Firepower Extensible Operating System (FXOS) 2.2.2.19, Cisco Firepower Extensible Operating System (FXOS) 2.2.2.24, Cisco Firepower Extensible Operating System (FXOS) 2.2.2.26, Cisco Firepower Extensible Operating System (FXOS) 2.2.2.28, Cisco Firepower Extensible Operating System (FXOS) 2.2.2.54, Cisco Firepower Extensible Operating System (FXOS) 2.2.2.60, Cisco Firepower Extensible Operating System (FXOS) 2.2.2.71, Cisco Firepower Extensible Operating System (FXOS) 2.2.2.83, Cisco Firepower Extensible Operating System (FXOS) 2.2.2.86, Cisco Firepower Extensible Operating System (FXOS) 2.2.2.91, Cisco Firepower Extensible Operating System (FXOS) 2.2.2.97, Cisco Firepower Extensible Operating System (FXOS) 2.2.2.101, Cisco Firepower Extensible Operating System (FXOS), Cisco Firepower 9000 Series, Cisco Firepower 4100 Series

Related Products

Product CVE Evidence
Firepower Extensible Operating System CVE-2020-3545 Cisco OpenVuln
Cisco Firepower Extensible Operating System (FXOS) CVE-2020-3545 Cisco OpenVuln
Cisco Firepower Extensible Operating System CVE-2020-3545 Cisco OpenVuln
Cisco Firepower 9000 Series CVE-2020-3545 Cisco OpenVuln
Cisco Firepower 4100 Series CVE-2020-3545 Cisco OpenVuln