CVE-2020-3253
published 2020-05-06CVE-2020-3253: A vulnerability in the support tunnel feature of Cisco Firepower Threat Defense (FTD) Software could allow an authenticated, local attacker to access the shell…
PriorityP431medium6.7CVSS 3.1
AVLACLPRHUINSUCHIHAH
EPSS
0.30%
22.8th percentile
A vulnerability in the support tunnel feature of Cisco Firepower Threat Defense (FTD) Software could allow an authenticated, local attacker to access the shell of an affected device even though expert mode is disabled. The vulnerability is due to improper configuration of the support tunnel feature. An attacker could exploit this vulnerability by enabling the support tunnel, setting a key, and deriving the tunnel password. A successful exploit could allow the attacker to run any system command with root access on an affected device.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | cisco_firepower_threat_defense_software | — | — |
| cisco | firepower_threat_defense | < 6.5.0 | 6.5.0 |
| cisco | firepower_threat_defense | — | — |
CVSS provenance
nvdv3.16.7MEDIUMCVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
nvdv3.06.7MEDIUMCVSS:3.0/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.2HIGHAV:L/AC:L/Au:N/C:C/I:C/A:C
vendor_oracle9.8CRITICAL
vendor_cisco6.7MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Cisco
Cisco Firepower Threat Defense Software Shell Access Vulnerability
vendor_cisco·2020-05-06·CVSS 6.7
CVE-2020-3253 [MEDIUM] CWE-284 Cisco Firepower Threat Defense Software Shell Access Vulnerability
Cisco Firepower Threat Defense Software Shell Access Vulnerability
A vulnerability in the support tunnel feature of Cisco Firepower Threat Defense (FTD) Software could allow an authenticated, local attacker to access the shell of an affected device even though expert mode is disabled.
The vulnerability is due to improper configuration of the support tunnel feature. An attacker could exploit this vulnerability by enabling the support tunnel, setting a key, and deriving the tunnel password. A successful exploit could allow the attacker to run any system command with root access on an affected device.
Cisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability.
This advisory is available at the following link:https://sec.clou
Oracle
Oracle Oracle Communications Applications Risk Matrix: Admin Console (Groovy) — CVE-2015-3253
vendor_oracle·2020-04-15·CVSS 9.8
CVE-2015-3253 [CRITICAL] Oracle Oracle Communications Applications Risk Matrix: Admin Console (Groovy) — CVE-2015-3253
Oracle Oracle Communications Applications Risk Matrix: Admin Console (Groovy) vulnerability
CVE: CVE-2015-3253
CVSS: 9.8
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpuapr2020 (APR 2020)
Cisco
Cisco Firepower Threat Defense Software Shell Access Vulnerability
vendor_cisco·CVSS 3.0
CVE-2020-3253 Cisco Firepower Threat Defense Software Shell Access Vulnerability
CVE-2020-3253: Cisco Firepower Threat Defense Software Shell Access Vulnerability
A vulnerability in the support tunnel feature of Cisco Firepower Threat Defense (FTD) Software could allow an authenticated, local attacker to access the shell of an affected device even though expert mode is disabled. The vulnerability is due to improper configuration of the support tunnel feature. An attacker could exploit this vulnerability by enabling the support tunnel, setting a key, and deriving the tunnel password. A successful exploit could allow the attacker to run any system command with root access on an affected device. Cisco has released software updates that address this vulnerability. There are no
CVSS: 3.0
CWE: CWE-284, CWE-284
Bug IDs: CSCvp16933
GHSA
GHSA-v33g-rjxr-6hm4: A vulnerability in the support tunnel feature of Cisco Firepower Threat Defense (FTD) Software could allow an authenticated, local attacker to access
ghsa_unreviewed·2022-05-24
CVE-2020-3253 [HIGH] GHSA-v33g-rjxr-6hm4: A vulnerability in the support tunnel feature of Cisco Firepower Threat Defense (FTD) Software could allow an authenticated, local attacker to access
A vulnerability in the support tunnel feature of Cisco Firepower Threat Defense (FTD) Software could allow an authenticated, local attacker to access the shell of an affected device even though expert mode is disabled. The vulnerability is due to improper configuration of the support tunnel feature. An attacker could exploit this vulnerability by enabling the support tunnel, setting a key, and deriving the tunnel password. A successful exploit could allow the attacker to run any system command with root access on an affected device.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2020-05-06
Published