cbcvebase.
CVE-2019-12687
published 2019-10-02

CVE-2019-12687: A vulnerability in the web UI of the Cisco Firepower Management Center (FMC) could allow an authenticated, remote attacker to execute arbitrary commands on an…

PriorityP260high8.8CVSS 3.1
AVNACLPRLUINSUCHIHAH
EPSS
3.39%
87.5th percentile
A vulnerability in the web UI of the Cisco Firepower Management Center (FMC) could allow an authenticated, remote attacker to execute arbitrary commands on an affected device. The vulnerability is due to insufficient input validation. An attacker could exploit this vulnerability by sending crafted input to the web UI. A successful exploit could allow the attacker to execute arbitrary commands within the affected device.

Affected

4 ranges
VendorProductVersion rangeFixed in
ciscocisco_firepower_management_center>= unspecified < n/an/a
ciscofirepower_management_center
ciscosecure_firewall_management_center
ciscosecure_firewall_management_center

Detection & IOCsextracted from sources · hover to see the quote

  • Exploit vector is crafted input sent to the Cisco FMC web UI by an authenticated remote attacker; monitor FMC web UI access logs for anomalous or malformed input from authenticated sessions
  • Root cause is insufficient input validation in the FMC web UI; focus detection on unexpected command execution processes spawned from the FMC web server process
  • Track Cisco bug IDs CSCvf87540 and CSCvg04183 for patch and version correlation when triaging affected FMC deployments
  • ·Exploitation requires prior authentication to the FMC web UI; unauthenticated access alone is insufficient to trigger this vulnerability
  • ·No workarounds exist; the only remediation is applying Cisco-released software updates

CVSS provenance

nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv3.08.8HIGHCVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv2.09.0CRITICALAV:N/AC:L/Au:S/C:C/I:C/A:C
vendor_cisco8.8HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.