CVE-2019-12688
published 2019-10-02CVE-2019-12688: A vulnerability in the web UI of the Cisco Firepower Management Center (FMC) could allow an authenticated, remote attacker to execute arbitrary commands on an…
PriorityP260high8.8CVSS 3.1
AVNACLPRLUINSUCHIHAH
EPSS
3.39%
87.4th percentile
A vulnerability in the web UI of the Cisco Firepower Management Center (FMC) could allow an authenticated, remote attacker to execute arbitrary commands on an affected device. The vulnerability is due to insufficient input validation. An attacker could exploit this vulnerability by sending crafted input to the web UI. A successful exploit could allow the attacker to execute arbitrary commands within the affected device.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | cisco_firepower_management_center | >= unspecified < n/a | n/a |
| cisco | firepower_management_center | — | — |
| cisco | secure_firewall_management_center | — | — |
Detection & IOCsextracted from sources · hover to see the quote
- →Vulnerability is exploited via crafted input sent to the Cisco FMC web UI by an authenticated remote attacker; monitor FMC web UI traffic for anomalous or malformed input submissions from authenticated sessions ↗
- →Cisco internal bug IDs CSCvf87540 and CSCvg04183 are associated with this vulnerability and can be used to cross-reference patch and advisory tracking ↗
- ·Exploitation requires an authenticated session; attack surface is limited to users with valid credentials to the FMC web UI, but post-authentication RCE makes privilege escalation or lateral movement a significant risk ↗
- ·There are no workarounds available; patching via Cisco software updates is the only remediation path ↗
CVSS provenance
nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv3.08.8HIGHCVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv2.09.0CRITICALAV:N/AC:L/Au:S/C:C/I:C/A:C
vendor_cisco8.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Cisco
Cisco Firepower Management Center Remote Code Execution Vulnerability
vendor_cisco·2019-10-02·CVSS 8.8
CVE-2019-12687 [HIGH] CWE-119 Cisco Firepower Management Center Remote Code Execution Vulnerability
Cisco Firepower Management Center Remote Code Execution Vulnerability
A vulnerability in the web UI of the Cisco Firepower Management Center (FMC) could allow an authenticated, remote attacker to execute arbitrary commands on an affected device.
The vulnerability is due to insufficient input validation. An attacker could exploit this vulnerability by sending crafted input to the web UI. A successful exploit could allow the attacker to execute arbitrary commands within the affected device.
Cisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability.
This advisory is available at the following link:
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20191002-fmc-rce
This advisory is part o
Cisco
Cisco Firepower Management Center Remote Code Execution Vulnerability
vendor_cisco·CVSS 3.0
CVE-2019-12688 Cisco Firepower Management Center Remote Code Execution Vulnerability
CVE-2019-12688: Cisco Firepower Management Center Remote Code Execution Vulnerability
A vulnerability in the web UI of the Cisco Firepower Management Center (FMC) could allow an authenticated, remote attacker to execute arbitrary commands on an affected device. The vulnerability is due to insufficient input validation. An attacker could exploit this vulnerability by sending crafted input to the web UI. A successful exploit could allow the attacker to execute arbitrary commands within the affected device. Cisco has released software updates that address this vulnerability. There are no
CVSS: 3.0
CWE: CWE-119, CWE-119
Bug IDs: CSCvf87540, CSCvg04183
GHSA
GHSA-9m45-vc7p-8mc6: A vulnerability in the web UI of the Cisco Firepower Management Center (FMC) could allow an authenticated, remote attacker to execute arbitrary comman
ghsa_unreviewed·2022-05-24
CVE-2019-12688 [HIGH] CWE-119 GHSA-9m45-vc7p-8mc6: A vulnerability in the web UI of the Cisco Firepower Management Center (FMC) could allow an authenticated, remote attacker to execute arbitrary comman
A vulnerability in the web UI of the Cisco Firepower Management Center (FMC) could allow an authenticated, remote attacker to execute arbitrary commands on an affected device. The vulnerability is due to insufficient input validation. An attacker could exploit this vulnerability by sending crafted input to the web UI. A successful exploit could allow the attacker to execute arbitrary commands within the affected device.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2019-10-02
Published