cbcvebase.
CVE-2021-1518
published 2021-07-22

CVE-2021-1518: A vulnerability in the REST API of Cisco Firepower Device Manager (FDM) On-Box Software could allow an authenticated, remote attacker to execute arbitrary code…

PriorityP261high8.8CVSS 3.1
AVNACLPRLUINSUCHIHAH
EPSS
1.87%
76.9th percentile
A vulnerability in the REST API of Cisco Firepower Device Manager (FDM) On-Box Software could allow an authenticated, remote attacker to execute arbitrary code on the underlying operating system of an affected device. This vulnerability is due to insufficient sanitization of user input on specific REST API commands. An attacker could exploit this vulnerability by sending a crafted HTTP request to the API subsystem of an affected device. A successful exploit could allow the attacker to execute arbitrary code on the underlying operating system. To exploit this vulnerability, an attacker would need valid low-privileged user credentials.

Affected

4 ranges
VendorProductVersion rangeFixed in
ciscocisco_firepower_threat_defense_software
ciscofirepower_device_manager_on-box
ciscofirepower_device_manager_on-box>= 6.3.0 < 6.4.06.4.0
ciscofirepower_device_manager_on-box>= 6.5.0 < 6.7.0.26.7.0.2

Detection & IOCsextracted from sources · hover to see the quote

  • Exploit vector is a crafted HTTP request targeting the REST API subsystem of Cisco FDM On-Box Software; monitor for anomalous or malformed REST API calls from authenticated low-privileged users
  • Exploitation requires valid low-privileged credentials; alert on REST API command execution originating from low-privilege accounts on Cisco FDM devices, especially those triggering OS-level process spawning
  • Root cause is insufficient input sanitization on specific REST API commands (CWE-94, code injection); focus detection on REST API endpoints accepting user-controlled input that may be passed to OS-level interpreters
  • ·Vulnerability is in Cisco Firepower Device Manager (FDM) On-Box Software REST API; only on-box FDM deployments are affected — not Firepower Management Center (FMC)-managed devices
  • ·Cisco Bug ID CSCvx44278 tracks this issue; use this identifier when cross-referencing vendor patch status or PSIRT advisories
  • ·No workarounds exist; patching via Cisco software updates is the only remediation

CVSS provenance

nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv2.09.0CRITICALAV:N/AC:L/Au:S/C:C/I:C/A:C
vendor_cisco6.3MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.