8.8highHigh
CVE-2019-12675
Cisco Secure Firewall Threat Defense
Multiple vulnerabilities in the multi-instance feature of Cisco Firepower Threat Defense (FTD) Software could allow an authenticated, local attacker to escape the container for their FTD instance and execute commands with root privileges in the host namespace. These vulnerabilities are due to insufficient protections on the underlying filesystem. An attacker could exploit these vulnerabilities by modifying critical files on the underlying filesystem. A successful exploit could allow the attacker to execute commands with root privileges within the host namespace. This could allow the attacker to impact other running FTD instances.
Exploitation status
- A vendor advisory or patch reference has been published.
What the metrics mean
- It is requires local access to the machine.
- For an attacker who can reach it, no special conditions are needed to exploit it.
- To exploit it, an ordinary user account is needed.
- Beyond that, no action by a user is required.
Scoring
- CVSS
- 8.8 (v3.1)
- Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H- Weakness
- CWE-216
- Assigned by
- psirt@cisco.com
Dates
- Published
- 2019-10-02
- Last modified
- 2026-08-11
- Sources
- NVD
Affected products
- Cisco Secure Firewall Threat Defense- 6.4.0.2
- Cisco Firepower 9300 Firmwareall versions
- Cisco Firepower 9300all versions
- Cisco Firepower 4115 Firmwareall versions
- Cisco Firepower 4115all versions
- Cisco Firepower 4125 Firmwareall versions
- Cisco Firepower 4125all versions
- Cisco Firepower 4145 Firmwareall versions
- Cisco Firepower 4145all versions
- Cisco Firepower 4110 Firmwareall versions
- Cisco Firepower 4110all versions
- Cisco Firepower 4120 Firmwareall versions
As listed in the NVD configuration data. Not a statement about your estate.