CVE-2020-3167OS Command Injection in Cisco Adaptive Security Appliance Software

Severity
7.8HIGHNVD
EPSS
0.3%
top 51.51%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedFeb 26
Latest updateMay 24

Description

A vulnerability in the CLI of Cisco FXOS Software and Cisco UCS Manager Software could allow an authenticated, local attacker to execute arbitrary commands on the underlying operating system (OS). The vulnerability is due to insufficient input validation. An attacker could exploit this vulnerability by including crafted arguments to specific commands. A successful exploit could allow the attacker to execute arbitrary commands on the underlying OS with the privileges of the currently logged-in us

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HExploitability: 1.8 | Impact: 5.9

Affected Packages5 packages

NVDcisco/ucs_manager4.04.0\(4g\)+1
NVDcisco/firepower_threat_defense6.2.26.2.3.13+2

🔴Vulnerability Details

2
GHSA
GHSA-x3p6-6j82-7c7q: A vulnerability in the CLI of Cisco FXOS Software and Cisco UCS Manager Software could allow an authenticated, local attacker to execute arbitrary com2022-05-24
CVEList
Cisco FXOS and UCS Manager Software CLI Command Injection Vulnerability2020-02-26

📋Vendor Advisories

1
Cisco
Cisco FXOS and UCS Manager Software CLI Command Injection Vulnerability2020-02-26
CVE-2020-3167 — OS Command Injection in Cisco | cvebase