CVE-2021-34752
published 2024-11-15CVE-2021-34752: A vulnerability in the CLI of Cisco FTD Software could allow an authenticated, local attacker with administrative privileges to execute arbitrary commands with…
PriorityP338medium6.7CVSS 3.1
AVLACLPRHUINSUCHIHAH
EPSS
0.26%
17.7th percentile
A vulnerability in the CLI of Cisco FTD Software could allow an authenticated, local attacker with administrative privileges to execute arbitrary commands with root privileges on the underlying operating system of an affected device.
This vulnerability is due to insufficient validation of user-supplied command arguments. An attacker could exploit this vulnerability by submitting crafted input to the affected commands. A successful exploit could allow the attacker to execute commands with root privileges on the underlying operating system.
Cisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | cisco_firepower_threat_defense_software | — | — |
| cisco | cisco_firepower_threat_defense_software | — | — |
| cisco | cisco_firepower_threat_defense_software | — | — |
| cisco | firepower_threat_defense | — | — |
CVSS provenance
nvdv3.16.7MEDIUMCVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
vendor_cisco7.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-2wh9-xh8x-vvv4: A vulnerability in the CLI of Cisco FTD Software could allow an authenticated, local attacker with administrative privileges to execute arbitrary comm
ghsa_unreviewed·2024-11-15
CVE-2021-34752 [MEDIUM] CWE-20 GHSA-2wh9-xh8x-vvv4: A vulnerability in the CLI of Cisco FTD Software could allow an authenticated, local attacker with administrative privileges to execute arbitrary comm
A vulnerability in the CLI of Cisco FTD Software could allow an authenticated, local attacker with administrative privileges to execute arbitrary commands with root privileges on the underlying operating system of an affected device.
This vulnerability is due to insufficient validation of user-supplied command arguments. An attacker could exploit this vulnerability by submitting crafted input to the affected commands. A successful exploit could allow the attacker to execute commands with root privileges on the underlying operating system.
Cisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability.
Cisco
Cisco Firepower Threat Defense Software Command Injection Vulnerabilities
vendor_cisco·2021-10-27·CVSS 7.8
CVE-2021-34752 [HIGH] CWE-20 Cisco Firepower Threat Defense Software Command Injection Vulnerabilities
Cisco Firepower Threat Defense Software Command Injection Vulnerabilities
Multiple vulnerabilities in the CLI of Cisco Firepower Threat Defense (FTD) Software could allow an authenticated, local attacker to execute arbitrary commands with root privileges.
For more information about these vulnerabilities, see the Details section of this advisory.
Cisco has released software updates that address these vulnerabilities. There are no workarounds that address these vulnerabilities.
This advisory is available at the following link:
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ftd-cmdinject-FmzsLN8
This advisory is part of the October 2021 release of the Cisco ASA, FTD, and FMC Security Advisory Bundled publication. For a complete list of the advisories a
Cisco
Cisco Firepower Threat Defense Software Command Injection Vulnerabilities
vendor_cisco·CVSS 3.1
CVE-2021-34752 Cisco Firepower Threat Defense Software Command Injection Vulnerabilities
CVE-2021-34752: Cisco Firepower Threat Defense Software Command Injection Vulnerabilities
Multiple vulnerabilities in the CLI of Cisco Firepower Threat Defense (FTD) Software could allow an authenticated, local attacker to execute arbitrary commands with root privileges. For more information about these vulnerabilities, see the
CVSS: 3.1
CWE: CWE-20, CWE-77, CWE-20, CWE-77
Bug IDs: CSCvx86283, CSCvy16559, CSCvy16573, CSCvx86283, CSCvy16559
No detection rules found.
No public exploits indexed.
Qualys
Microsoft Windows Print Spooler RCE Vulnerability (PrintNightmare-CVE-2021-34527) – Automatically Discover, Prioritize and Remediate Using Qualys VMDR®
blogs_qualys·2021-07-07·CVSS 8.8
CVE-2021-34527 [HIGH] Microsoft Windows Print Spooler RCE Vulnerability (PrintNightmare-CVE-2021-34527) – Automatically Discover, Prioritize and Remediate Using Qualys VMDR®
## Table of Contents
About PrintNightmare
Affected Products
Identify Assets, Discover, Prioritize and Remediate Using Qualys VMDR
Identification of Windows Assets with Print Spooler Running
Discover PrintNightmare CVE-2021-34527 Vulnerability
Dashboard
Response by Patching and Remediation
Identify and Address System Misconfigurations
Registry Settings Check After Installing the Updates
Workaround
Get Started Now
Update July 9, 2021 : Added “Registry Settings Check After Installing the Updates” section below.
Original Post : On June 29, 2021, a zero-day exploit was observed on Microsoft Windows systems which allows authenticated users with a regular Domain User account to gain full SYSTEM-level privileges. On July 1, 2021, Microsoft released a separate advisory linking this zer
Qualys
Microsoft Windows Print Spooler RCE Vulnerability (PrintNightmare-CVE-2021-34527) – Automatically Discover, Prioritize and Remediate Using Qualys VMDR® | Qualys
blogs_qualys·2021-07-07·CVSS 8.8
CVE-2021-34527 [HIGH] Microsoft Windows Print Spooler RCE Vulnerability (PrintNightmare-CVE-2021-34527) – Automatically Discover, Prioritize and Remediate Using Qualys VMDR® | Qualys
#### Table of Contents
- About PrintNightmare
- Affected Products
- Identify Assets, Discover, Prioritize and Remediate Using Qualys VMDR
- Identification of Windows Assets with Print Spooler Running
- Discover PrintNightmare CVE-2021-34527 Vulnerability
- Dashboard
- Response by Patching and Remediation
- Identify and Address System Misconfigurations
- Registry Settings Check After Installing the Updates
- Workaround
- Get Started Now
Update July 9, 2021: Added “Registry Settings Check After Installing the Updates” section below.
Original Post: On June 29, 2021, a zero-day exploit was observed on Microsoft Windows systems which allows authenticated users with a regular Domain User account to gain full SYSTEM-level privileges. On July 1, 2021, Microsoft released a separate advisory link
2024-11-15
Published