cbcvebase.
CVE-2019-12689
published 2019-10-02

CVE-2019-12689: A vulnerability in the web-based management interface of Cisco Firepower Management Center (FMC) Software could allow an authenticated, remote attacker to…

PriorityP261high8.8CVSS 3.1
AVNACLPRLUINSUCHIHAH
EPSS
3.12%
86.4th percentile
A vulnerability in the web-based management interface of Cisco Firepower Management Center (FMC) Software could allow an authenticated, remote attacker to execute arbitrary code on the underlying operating system of an affected device. The vulnerability is due to insufficient input validation. An attacker could exploit this vulnerability by sending malicious commands to the web-based management interface of an affected device. A successful exploit could allow the attacker to execute arbitrary code on the underlying operating system of the affected device.

Affected

3 ranges
VendorProductVersion rangeFixed in
ciscocisco_firepower_management_center>= unspecified < n/an/a
ciscofirepower_management_center
ciscosecure_firewall_management_center< 6.2.2.26.2.2.2

Detection & IOCsextracted from sources · hover to see the quote

  • Exploit vector is authenticated HTTP requests containing malicious commands sent to the Cisco FMC web-based management interface; monitor for anomalous or unexpected command injection patterns in FMC web UI traffic
  • Requires authenticated session — correlate with unusual authenticated user activity or privilege escalation on Cisco FMC; alert on OS-level command execution spawned from FMC web server processes
  • ·No workarounds are available for this vulnerability; patching via Cisco software updates is the only mitigation
  • ·This CVE is tracked under Cisco Bug ID CSCvh03951 and is part of the October 2019 Cisco ASA, FMC, and FTD bundled advisory covering 18 vulnerabilities across 10 advisories — review the full bundle for related exposure

CVSS provenance

nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv3.07.5HIGHCVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv2.09.0CRITICALAV:N/AC:L/Au:S/C:C/I:C/A:C
vendor_cisco7.5HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.