cbcvebase.

Cisco Firepower Extensible Operating System vulnerabilities

52 known vulnerabilities affecting cisco/firepower_extensible_operating_system.

Total CVEs
52
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL2HIGH22MEDIUM28

Vulnerabilities

Page 1 of 3
CVE-2015-6435P2CRITICALCVSS 9.8v1.1\(1.86\)v1.1\(1.160\)+1 more2016-01-22
CVE-2015-6435 [CRITICAL] CWE-78 CVE-2015-6435: An unspecified CGI script in Cisco FX-OS before 1.1.2 on Firepower 9000 devices and Cisco Unified Co An unspecified CGI script in Cisco FX-OS before 1.1.2 on Firepower 9000 devices and Cisco Unified Computing System (UCS) Manager before 2.2(4b), 2.2(5) before 2.2(5a), and 3.0 before 3.0(2e) allows remote attackers to execute arbitrary shell commands via a crafted HTTP request, aka Bug ID CSCur90888.
nvd
CVE-2017-12277P2HIGHCVSS 8.8≤ 1.1.3v1.1.4+1 more2017-11-02
CVE-2017-12277 [HIGH] CWE-20 CVE-2017-12277: A vulnerability in the Smart Licensing Manager service of the Cisco Firepower 4100 Series Next-Gener A vulnerability in the Smart Licensing Manager service of the Cisco Firepower 4100 Series Next-Generation Firewall (NGFW) and Firepower 9300 Security Appliance could allow an authenticated, remote attacker to inject arbitrary commands that could be executed with root privileges. The vulnerability is due to insufficient input validation of certain Smart
nvd
CVE-2018-0310P3CRITICALCVSS 9.8≥ 1.1, < 1.1.4.179≥ 2.0, < 2.0.1.153+3 more2018-06-21
CVE-2018-0310 [CRITICAL] CWE-399 CVE-2018-0310: A vulnerability in the Cisco Fabric Services component of Cisco FXOS Software and Cisco NX-OS Softwa A vulnerability in the Cisco Fabric Services component of Cisco FXOS Software and Cisco NX-OS Software could allow an unauthenticated, remote attacker to obtain sensitive information from memory or cause a denial of service (DoS) condition on the affected product. The vulnerability exists because the affected software insufficiently validates header
nvd
CVE-2020-3172P3HIGHCVSS 8.8fixed in 2.6.1.187≥ 2.7, < 2.7.1.1062020-02-26
CVE-2020-3172 [HIGH] CWE-20 CVE-2020-3172: A vulnerability in the Cisco Discovery Protocol feature of Cisco FXOS Software and Cisco NX-OS Softw A vulnerability in the Cisco Discovery Protocol feature of Cisco FXOS Software and Cisco NX-OS Software could allow an unauthenticated, adjacent attacker to execute arbitrary code as root or cause a denial of service (DoS) condition on an affected device. The vulnerability exists because of insufficiently validated Cisco Discovery Protocol packet headers
nvd
CVE-2017-3883P3HIGHCVSS 8.6≤ 2.32017-10-19
CVE-2017-3883 [HIGH] CWE-770 CVE-2017-3883: A vulnerability in the authentication, authorization, and accounting (AAA) implementation of Cisco F A vulnerability in the authentication, authorization, and accounting (AAA) implementation of Cisco Firepower Extensible Operating System (FXOS) and NX-OS System Software could allow an unauthenticated, remote attacker to cause an affected device to reload. The vulnerability occurs because AAA processes prevent the NX-OS System Manager from receiving kee
nvd
CVE-2021-1368P3HIGHCVSS 8.8vr2312021-02-24
CVE-2021-1368 [HIGH] CWE-787 CVE-2021-1368: A vulnerability in the Unidirectional Link Detection (UDLD) feature of Cisco FXOS Software and Cisco A vulnerability in the Unidirectional Link Detection (UDLD) feature of Cisco FXOS Software and Cisco NX-OS Software could allow an unauthenticated, adjacent attacker to execute arbitrary code with administrative privileges or cause a denial of service (DoS) condition on an affected device. This vulnerability is due to insufficient input validation. An a
nvd
CVE-2018-0303P3HIGHCVSS 8.8≥ 1.1, < 1.1.4.179≥ 2.0, < 2.0.1.153+3 more2018-06-21
CVE-2018-0303 [HIGH] CWE-20 CVE-2018-0303: A vulnerability in the Cisco Discovery Protocol component of Cisco FXOS Software and Cisco NX-OS Sof A vulnerability in the Cisco Discovery Protocol component of Cisco FXOS Software and Cisco NX-OS Software could allow an unauthenticated, adjacent attacker to execute arbitrary code as root or cause a denial of service (DoS) condition on the affected device. The vulnerability exists because of insufficiently validated Cisco Discovery Protocol packet head
nvd
CVE-2020-3517P3HIGHCVSS 8.6≥ 1.1, < 1.1.4.179≥ 2.0, < 2.0.1.153+2 more2020-08-27
CVE-2020-3517 [HIGH] CWE-476 CVE-2020-3517: A vulnerability in the Cisco Fabric Services component of Cisco FXOS Software and Cisco NX-OS Softwa A vulnerability in the Cisco Fabric Services component of Cisco FXOS Software and Cisco NX-OS Software could allow an unauthenticated attacker to cause process crashes, which could result in a denial of service (DoS) condition on an affected device. The attack vector is configuration dependent and could be remote or adjacent. For more information about
nvd
CVE-2020-3456P3HIGHCVSS 8.8v2.4\(1.249\)2020-10-21
CVE-2020-3456 [HIGH] CWE-352 CVE-2020-3456: A vulnerability in the Cisco Firepower Chassis Manager (FCM) of Cisco FXOS Software could allow an u A vulnerability in the Cisco Firepower Chassis Manager (FCM) of Cisco FXOS Software could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack against a user of an affected device. The vulnerability is due to insufficient CSRF protections for the FCM interface. An attacker could exploit this vulnerability by pe
nvd
CVE-2019-1858P3HIGHCVSS 8.6≥ 2.6, < 2.6.1.1312019-05-16
CVE-2019-1858 [HIGH] CWE-20 CVE-2019-1858: A vulnerability in the Simple Network Management Protocol (SNMP) input packet processor of Cisco FXO A vulnerability in the Simple Network Management Protocol (SNMP) input packet processor of Cisco FXOS Software and Cisco NX-OS Software could allow an unauthenticated, remote attacker to cause the SNMP application to leak system memory, which could cause an affected device to restart unexpectedly. The vulnerability is due to improper error handling when
nvd
CVE-2019-1598P3HIGHCVSS 7.5≥ 2.3, < 2.3.1.75≥ 2.1, < 2.2.2.54+1 more2019-03-07
CVE-2019-1598 [HIGH] CWE-20 CVE-2019-1598: Multiple vulnerabilities in the implementation of the Lightweight Directory Access Protocol (LDAP) f Multiple vulnerabilities in the implementation of the Lightweight Directory Access Protocol (LDAP) feature in Cisco FXOS Software and Cisco NX-OS Software could allow an unauthenticated, remote attacker to cause an affected device to reload, resulting in a denial of service (DoS) condition. The vulnerabilities are due to the improper parsing of LDAP pack
nvd
CVE-2019-1597P3HIGHCVSS 7.5fixed in 2.3.1.75fixed in 2.2.2.54+1 more2019-03-07
CVE-2019-1597 [HIGH] CWE-20 CVE-2019-1597: Multiple vulnerabilities in the implementation of the Lightweight Directory Access Protocol (LDAP) f Multiple vulnerabilities in the implementation of the Lightweight Directory Access Protocol (LDAP) feature in Cisco FXOS Software and Cisco NX-OS Software could allow an unauthenticated, remote attacker to cause an affected device to reload, resulting in a denial of service (DoS) condition. The vulnerabilities are due to the improper parsing of LDAP pack
nvd
CVE-2018-0311P3HIGHCVSS 7.5≥ 1.1, < 1.1.4.179≥ 2.0, < 2.0.1.153+3 more2018-06-21
CVE-2018-0311 [HIGH] CWE-399 CVE-2018-0311: A vulnerability in the Cisco Fabric Services component of Cisco FXOS Software and Cisco NX-OS Softwa A vulnerability in the Cisco Fabric Services component of Cisco FXOS Software and Cisco NX-OS Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. The vulnerability exists because the affected software insufficiently validates Cisco Fabric Services packets when the software processe
nvd
CVE-2020-3167P3HIGHCVSS 7.8fixed in 2.4.1.2342020-02-26
CVE-2020-3167 [HIGH] CWE-78 CVE-2020-3167: A vulnerability in the CLI of Cisco FXOS Software and Cisco UCS Manager Software could allow an auth A vulnerability in the CLI of Cisco FXOS Software and Cisco UCS Manager Software could allow an authenticated, local attacker to execute arbitrary commands on the underlying operating system (OS). The vulnerability is due to insufficient input validation. An attacker could exploit this vulnerability by including crafted arguments to specific commands. A
nvd
CVE-2019-12699P3HIGHCVSS 7.8≥ 2.0, < 2.2.2.101≥ 2.3, < 2.3.1.155+1 more2019-10-02
CVE-2019-12699 [HIGH] CWE-20 CVE-2019-12699: Multiple vulnerabilities in the CLI of Cisco FXOS Software and Cisco Firepower Threat Defense (FTD) Multiple vulnerabilities in the CLI of Cisco FXOS Software and Cisco Firepower Threat Defense (FTD) Software could allow an authenticated, local attacker to execute commands on the underlying operating system (OS) with root privileges. These vulnerabilities are due to insufficient input validation. An attacker could exploit these vulnerabilities by incl
nvd
CVE-2020-3459P3HIGHCVSS 7.8fixed in 2.4.1.266≥ 2.6, < 2.6.1.204+2 more2020-10-21
CVE-2020-3459 [HIGH] CWE-78 CVE-2020-3459: A vulnerability in the CLI of Cisco FXOS Software could allow an authenticated, local attacker to in A vulnerability in the CLI of Cisco FXOS Software could allow an authenticated, local attacker to inject arbitrary commands that are executed with root privileges. The vulnerability is due to insufficient input validation of commands supplied by the user. An attacker could exploit this vulnerability by authenticating to a device and submitting crafted in
nvd
CVE-2018-0298P3HIGHCVSS 7.5≥ 1.1, < 1.1.4.169≥ 2.0, < 2.0.1.135+2 more2018-06-21
CVE-2018-0298 [HIGH] CWE-20 CVE-2018-0298: A vulnerability in the web UI of Cisco FXOS and Cisco UCS Fabric Interconnect Software could allow a A vulnerability in the web UI of Cisco FXOS and Cisco UCS Fabric Interconnect Software could allow an unauthenticated, remote attacker to cause a buffer overflow on an affected system. The vulnerability is due to incorrect input validation in the web UI. An attacker could exploit this vulnerability by sending a malicious HTTP or HTTPS packet directed to
nvd
CVE-2018-0302P3HIGHCVSS 7.8≥ 1.1, < 1.1.4.169≥ 2.0, < 2.0.1.1352018-06-21
CVE-2018-0302 [HIGH] CWE-20 CVE-2018-0302: A vulnerability in the CLI parser of Cisco FXOS Software and Cisco UCS Fabric Interconnect Software A vulnerability in the CLI parser of Cisco FXOS Software and Cisco UCS Fabric Interconnect Software could allow an authenticated, local attacker to cause a buffer overflow on an affected device. The vulnerability is due to incorrect input validation in the CLI parser subsystem. An attacker could exploit this vulnerability by exceeding the expected length
nvd
CVE-2020-3455P3HIGHCVSS 7.8fixed in 2.4.1.268≥ 2.6, < 2.6.1.214+1 more2020-10-21
CVE-2020-3455 [HIGH] CWE-693 CVE-2020-3455: A vulnerability in the secure boot process of Cisco FXOS Software could allow an authenticated, loca A vulnerability in the secure boot process of Cisco FXOS Software could allow an authenticated, local attacker to bypass the secure boot mechanisms. The vulnerability is due to insufficient protections of the secure boot process. An attacker could exploit this vulnerability by injecting code into a specific file that is then referenced during the device
nvd
CVE-2017-6597P3HIGHCVSS 7.8v2.0\(1.68\)2017-04-07
CVE-2017-6597 [HIGH] CWE-78 CVE-2017-6597: A vulnerability in the local-mgmt CLI command of the Cisco Unified Computing System (UCS) Manager, C A vulnerability in the local-mgmt CLI command of the Cisco Unified Computing System (UCS) Manager, Cisco Firepower 4100 Series Next-Generation Firewall (NGFW), and Cisco Firepower 9300 Security Appliance could allow an authenticated, local attacker to perform a command injection attack. More Information: CSCvb61394 CSCvb86816. Known Affected Releases: 2.
nvd
Cisco Firepower Extensible Operating System vulnerabilities | cvebase