Vulnslist

Cisco vulnerabilities by product, model, software, and advisory.

CVE-2022-20934

A vulnerability in the CLI of Cisco Firepower Threat Defense (FTD) Software and Cisco FXOS Software could allow an authenticated, local attacker to execute arbitrary commands on the underlying operating system as root. This vulnerability is due to improper input validation for specific CLI commands. An attacker could exploit this vulnerability by injecting operating system commands into a legitimate command. A successful exploit could allow the attacker to escape the restricted command prompt and execute arbitrary commands on the underlying operating system. To successfully exploit this vulnerability, an attacker would need valid Administrator credentials.

SeverityMEDIUM
CVSS6.0
CWECWE-77
KEV
Published
Modified

Related Products

Product Advisory Evidence
Firepower Extensible Operating System cisco-sa-ftd-fxos-cmd-inj-Q9bLNsrK Cisco OpenVuln
Cisco Secure Firewall Threat Defense Virtual cisco-sa-ftd-fxos-cmd-inj-Q9bLNsrK Cisco OpenVuln
Cisco Secure Firewall Threat Defense (FTD) Software cisco-sa-ftd-fxos-cmd-inj-Q9bLNsrK Cisco OpenVuln
Cisco Secure Firewall 3100 Series cisco-sa-ftd-fxos-cmd-inj-Q9bLNsrK Cisco OpenVuln
Cisco Firepower Threat Defense Software cisco-sa-ftd-fxos-cmd-inj-Q9bLNsrK Cisco OpenVuln
Cisco Firepower Extensible Operating System (FXOS) cisco-sa-ftd-fxos-cmd-inj-Q9bLNsrK Cisco OpenVuln
Cisco Firepower Extensible Operating System cisco-sa-ftd-fxos-cmd-inj-Q9bLNsrK Cisco OpenVuln
Cisco Firepower 9000 Series cisco-sa-ftd-fxos-cmd-inj-Q9bLNsrK Cisco OpenVuln
Cisco Firepower 4100 Series cisco-sa-ftd-fxos-cmd-inj-Q9bLNsrK Cisco OpenVuln
Cisco Firepower 2100 Series cisco-sa-ftd-fxos-cmd-inj-Q9bLNsrK Cisco OpenVuln
Cisco Firepower 1000 Series cisco-sa-ftd-fxos-cmd-inj-Q9bLNsrK Cisco OpenVuln
Cisco ASA 5500-X Series Firewalls cisco-sa-ftd-fxos-cmd-inj-Q9bLNsrK Cisco OpenVuln
Cisco 3000 Series Industrial Security Appliances (ISA) cisco-sa-ftd-fxos-cmd-inj-Q9bLNsrK Cisco OpenVuln