7.8highHigh
CVE-2019-12699
Cisco Firepower 9300 Firmware
Multiple vulnerabilities in the CLI of Cisco FXOS Software and Cisco Firepower Threat Defense (FTD) Software could allow an authenticated, local attacker to execute commands on the underlying operating system (OS) with root privileges. These vulnerabilities are due to insufficient input validation. An attacker could exploit these vulnerabilities by including crafted arguments to specific CLI commands. A successful exploit could allow the attacker to execute commands on the underlying OS with root privileges.
Exploitation status
- A vendor advisory or patch reference has been published.
What the metrics mean
- It is requires local access to the machine.
- For an attacker who can reach it, no special conditions are needed to exploit it.
- To exploit it, an ordinary user account is needed.
- Beyond that, no action by a user is required.
Scoring
- CVSS
- 7.8 (v3.1)
- Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H- Weakness
- CWE-20
- Assigned by
- psirt@cisco.com
Dates
- Published
- 2019-10-02
- Last modified
- 2026-08-11
- Sources
- NVD
Affected products
- Cisco Firepower 9300 Firmware2.4\(1.214\), 2.4\(1.216\), 2.4\(2.54\), r241
- Cisco Firepower 9300all versions
- Cisco Secure Firewall Threat Defense- 6.1.0, 6.2.0 - 6.2.3.14, 6.3.0 - 6.3.0.3
- Cisco Firepower 1000all versions
- Cisco Firepower 2100all versions
- Cisco Firepower Extensible Operating System2.0 - 2.2.2.101, 2.3 - 2.3.1.155, 2.4 - 2.4.1.238
- Cisco Firepower 4100all versions
As listed in the NVD configuration data. Not a statement about your estate.