CVE-2019-12689
published 2019-10-02CVE-2019-12689: A vulnerability in the web-based management interface of Cisco Firepower Management Center (FMC) Software could allow an authenticated, remote attacker to…
PriorityP261high8.8CVSS 3.1
AVNACLPRLUINSUCHIHAH
EPSS
3.12%
86.4th percentile
A vulnerability in the web-based management interface of Cisco Firepower Management Center (FMC) Software could allow an authenticated, remote attacker to execute arbitrary code on the underlying operating system of an affected device. The vulnerability is due to insufficient input validation. An attacker could exploit this vulnerability by sending malicious commands to the web-based management interface of an affected device. A successful exploit could allow the attacker to execute arbitrary code on the underlying operating system of the affected device.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | cisco_firepower_management_center | >= unspecified < n/a | n/a |
| cisco | firepower_management_center | — | — |
| cisco | secure_firewall_management_center | < 6.2.2.2 | 6.2.2.2 |
Detection & IOCsextracted from sources · hover to see the quote
- →Exploit vector is authenticated HTTP requests containing malicious commands sent to the Cisco FMC web-based management interface; monitor for anomalous or unexpected command injection patterns in FMC web UI traffic ↗
- →Requires authenticated session — correlate with unusual authenticated user activity or privilege escalation on Cisco FMC; alert on OS-level command execution spawned from FMC web server processes ↗
- ·No workarounds are available for this vulnerability; patching via Cisco software updates is the only mitigation ↗
- ·This CVE is tracked under Cisco Bug ID CSCvh03951 and is part of the October 2019 Cisco ASA, FMC, and FTD bundled advisory covering 18 vulnerabilities across 10 advisories — review the full bundle for related exposure ↗
CVSS provenance
nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv3.07.5HIGHCVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv2.09.0CRITICALAV:N/AC:L/Au:S/C:C/I:C/A:C
vendor_cisco7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-7p39-4wj4-xxhg: A vulnerability in the web-based management interface of Cisco Firepower Management Center (FMC) Software could allow an authenticated, remote attacke
ghsa_unreviewed·2022-05-24
CVE-2019-12689 [HIGH] CWE-20 GHSA-7p39-4wj4-xxhg: A vulnerability in the web-based management interface of Cisco Firepower Management Center (FMC) Software could allow an authenticated, remote attacke
A vulnerability in the web-based management interface of Cisco Firepower Management Center (FMC) Software could allow an authenticated, remote attacker to execute arbitrary code on the underlying operating system of an affected device. The vulnerability is due to insufficient input validation. An attacker could exploit this vulnerability by sending malicious commands to the web-based management interface of an affected device. A successful exploit could allow the attacker to execute arbitrary code on the underlying operating system of the affected device.
Cisco
Cisco Firepower Management Center Remote Code Execution Vulnerability
vendor_cisco·2019-10-02·CVSS 7.5
CVE-2019-12689 [HIGH] CWE-20 Cisco Firepower Management Center Remote Code Execution Vulnerability
Cisco Firepower Management Center Remote Code Execution Vulnerability
A vulnerability in the web-based management interface of Cisco Firepower Management Center (FMC) Software could allow an authenticated, remote attacker to execute arbitrary code on the underlying operating system of an affected device.
The vulnerability is due to insufficient input validation. An attacker could exploit this vulnerability by sending malicious commands to the web-based management interface of an affected device. A successful exploit could allow the attacker to execute arbitrary code on the underlying operating system of the affected device.
Cisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability.
This advisory is available at the follow
Cisco
Cisco Firepower Management Center Remote Code Execution Vulnerability
vendor_cisco·CVSS 3.0
CVE-2019-12689 Cisco Firepower Management Center Remote Code Execution Vulnerability
CVE-2019-12689: Cisco Firepower Management Center Remote Code Execution Vulnerability
A vulnerability in the web-based management interface of Cisco Firepower Management Center (FMC) Software could allow an authenticated, remote attacker to execute arbitrary code on the underlying operating system of an affected device. The vulnerability is due to insufficient input validation. An attacker could exploit this vulnerability by sending malicious commands to the web-based management interface of an affected device. A successful exploit could allow the attacker to execute arbitrary code on the underlying operating system of the affected device. Cisco has released software updates that address this vulnerability. There are no
CVSS: 3.0
CWE: CWE-20, CWE-20
Bug IDs: CSCvh03951
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2019-10-02
Published