Cisco Firepower Extensible Operating System vulnerabilities

52 known vulnerabilities affecting cisco/firepower_extensible_operating_system.

Total CVEs
52
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL2HIGH22MEDIUM28

Vulnerabilities

Page 2 of 3
CVE-2019-1780MEDIUMCVSS 6.7fixed in 2.3.1.130≥ 2.4, < 2.4.1.1222019-05-16
CVE-2019-1780 [MEDIUM] CWE-77 CVE-2019-1780: A vulnerability in the CLI of Cisco FXOS Software and Cisco NX-OS Software could allow an authentica A vulnerability in the CLI of Cisco FXOS Software and Cisco NX-OS Software could allow an authenticated, local attacker with administrator credentials to execute arbitrary commands on the underlying operating system of an affected device with elevated privileges. The vulnerability is due to insufficient validation of arguments passed to certain CLI com
nvd
CVE-2019-1795MEDIUMCVSS 6.7fixed in 2.0.1.201≥ 2.1, < 2.2.2.54+2 more2019-05-15
CVE-2019-1795 [MEDIUM] CWE-77 CVE-2019-1795: A vulnerability in the CLI of Cisco FXOS Software and Cisco NX-OS Software could allow an authentica A vulnerability in the CLI of Cisco FXOS Software and Cisco NX-OS Software could allow an authenticated, local attacker to execute arbitrary commands on the underlying Linux operating system with the privilege level of root. The vulnerability is due to insufficient validation of arguments passed to a specific CLI command on the affected device. An atta
nvd
CVE-2019-1779MEDIUMCVSS 6.7fixed in 2.4.1.1012019-05-15
CVE-2019-1779 [MEDIUM] CWE-77 CVE-2019-1779: A vulnerability in the CLI of Cisco FXOS Software and Cisco NX-OS Software could allow an authentica A vulnerability in the CLI of Cisco FXOS Software and Cisco NX-OS Software could allow an authenticated, local attacker to execute arbitrary commands on the underlying operating system of an affected device with elevated privileges. The vulnerability is due to insufficient validation of arguments passed to certain CLI commands. An attacker could exploi
nvd
CVE-2019-1598HIGHCVSS 7.5≥ 2.3, < 2.3.1.75≥ 2.1, < 2.2.2.54+1 more2019-03-07
CVE-2019-1598 [HIGH] CWE-20 CVE-2019-1598: Multiple vulnerabilities in the implementation of the Lightweight Directory Access Protocol (LDAP) f Multiple vulnerabilities in the implementation of the Lightweight Directory Access Protocol (LDAP) feature in Cisco FXOS Software and Cisco NX-OS Software could allow an unauthenticated, remote attacker to cause an affected device to reload, resulting in a denial of service (DoS) condition. The vulnerabilities are due to the improper parsing of LDAP pack
nvd
CVE-2019-1597HIGHCVSS 7.5fixed in 2.3.1.75fixed in 2.2.2.54+1 more2019-03-07
CVE-2019-1597 [HIGH] CWE-20 CVE-2019-1597: Multiple vulnerabilities in the implementation of the Lightweight Directory Access Protocol (LDAP) f Multiple vulnerabilities in the implementation of the Lightweight Directory Access Protocol (LDAP) feature in Cisco FXOS Software and Cisco NX-OS Software could allow an unauthenticated, remote attacker to cause an affected device to reload, resulting in a denial of service (DoS) condition. The vulnerabilities are due to the improper parsing of LDAP pack
nvd
CVE-2019-1600MEDIUMCVSS 4.4≥ 1.1, < 2.2.2.91≥ 2.3, < 2.3.1.1102019-03-07
CVE-2019-1600 [MEDIUM] CWE-264 CVE-2019-1600: A vulnerability in the file system permissions of Cisco FXOS Software and Cisco NX-OS Software could A vulnerability in the file system permissions of Cisco FXOS Software and Cisco NX-OS Software could allow an authenticated, local attacker to access sensitive information that is stored in the file system of an affected system. The vulnerability is due to improper implementation of file system permissions. An attacker could exploit this vulnerability
nvd
CVE-2018-0395MEDIUMCVSS 5.3vr2312018-10-17
CVE-2018-0395 [HIGH] CWE-20 CVE-2018-0395: A vulnerability in the Link Layer Discovery Protocol (LLDP) implementation for Cisco FXOS Software a A vulnerability in the Link Layer Discovery Protocol (LLDP) implementation for Cisco FXOS Software and Cisco NX-OS Software could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) condition when the device unexpectedly reloads. The vulnerability is due to improper input validation of certain type, length, value (TLV) fields o
nvd
CVE-2018-0310CRITICALCVSS 9.8≥ 1.1, < 1.1.4.179≥ 2.0, < 2.0.1.153+3 more2018-06-21
CVE-2018-0310 [CRITICAL] CWE-399 CVE-2018-0310: A vulnerability in the Cisco Fabric Services component of Cisco FXOS Software and Cisco NX-OS Softwa A vulnerability in the Cisco Fabric Services component of Cisco FXOS Software and Cisco NX-OS Software could allow an unauthenticated, remote attacker to obtain sensitive information from memory or cause a denial of service (DoS) condition on the affected product. The vulnerability exists because the affected software insufficiently validates header
nvd
CVE-2018-0311HIGHCVSS 7.5≥ 1.1, < 1.1.4.179≥ 2.0, < 2.0.1.153+3 more2018-06-21
CVE-2018-0311 [HIGH] CWE-399 CVE-2018-0311: A vulnerability in the Cisco Fabric Services component of Cisco FXOS Software and Cisco NX-OS Softwa A vulnerability in the Cisco Fabric Services component of Cisco FXOS Software and Cisco NX-OS Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. The vulnerability exists because the affected software insufficiently validates Cisco Fabric Services packets when the software processe
nvd
CVE-2018-0303HIGHCVSS 8.8≥ 1.1, < 1.1.4.179≥ 2.0, < 2.0.1.153+3 more2018-06-21
CVE-2018-0303 [HIGH] CWE-20 CVE-2018-0303: A vulnerability in the Cisco Discovery Protocol component of Cisco FXOS Software and Cisco NX-OS Sof A vulnerability in the Cisco Discovery Protocol component of Cisco FXOS Software and Cisco NX-OS Software could allow an unauthenticated, adjacent attacker to execute arbitrary code as root or cause a denial of service (DoS) condition on the affected device. The vulnerability exists because of insufficiently validated Cisco Discovery Protocol packet head
nvd
CVE-2018-0302HIGHCVSS 7.8≥ 1.1, < 1.1.4.169≥ 2.0, < 2.0.1.1352018-06-21
CVE-2018-0302 [HIGH] CWE-20 CVE-2018-0302: A vulnerability in the CLI parser of Cisco FXOS Software and Cisco UCS Fabric Interconnect Software A vulnerability in the CLI parser of Cisco FXOS Software and Cisco UCS Fabric Interconnect Software could allow an authenticated, local attacker to cause a buffer overflow on an affected device. The vulnerability is due to incorrect input validation in the CLI parser subsystem. An attacker could exploit this vulnerability by exceeding the expected length
nvd
CVE-2018-0298HIGHCVSS 7.5≥ 1.1, < 1.1.4.169≥ 2.0, < 2.0.1.135+2 more2018-06-21
CVE-2018-0298 [HIGH] CWE-20 CVE-2018-0298: A vulnerability in the web UI of Cisco FXOS and Cisco UCS Fabric Interconnect Software could allow a A vulnerability in the web UI of Cisco FXOS and Cisco UCS Fabric Interconnect Software could allow an unauthenticated, remote attacker to cause a buffer overflow on an affected system. The vulnerability is due to incorrect input validation in the web UI. An attacker could exploit this vulnerability by sending a malicious HTTP or HTTPS packet directed to
nvd
CVE-2018-0331MEDIUMCVSS 6.5≥ 1.1, < 2.0.1.153≥ 2.1.1, < 2.1.1.86+1 more2018-06-21
CVE-2018-0331 [MEDIUM] CWE-399 CVE-2018-0331: A vulnerability in the Cisco Discovery Protocol (formerly known as CDP) subsystem of devices running A vulnerability in the Cisco Discovery Protocol (formerly known as CDP) subsystem of devices running, or based on, Cisco NX-OS Software contain a vulnerability that could allow an unauthenticated, adjacent attacker to create a denial of service (DoS) condition. The vulnerability is due to a failure to properly validate certain fields within a Cisco Di
nvd
CVE-2018-0294MEDIUMCVSS 6.7≥ 2.1.1, < 2.1.1.86≥ 2.2, < 2.2.2.172018-06-20
CVE-2018-0294 [MEDIUM] CWE-264 CVE-2018-0294: A vulnerability in the write-erase feature of Cisco FXOS Software and Cisco NX-OS Software could all A vulnerability in the write-erase feature of Cisco FXOS Software and Cisco NX-OS Software could allow an authenticated, local attacker to configure an unauthorized administrator account for an affected device. The vulnerability exists because the affected software does not properly delete sensitive files when certain CLI commands are used to clear th
nvd
CVE-2017-12299MEDIUMCVSS 5.3v2.2\(1.58\)2017-11-16
CVE-2017-12299 [MEDIUM] CWE-20 CVE-2017-12299: A vulnerability exists in the process of creating default IP blocks during device initialization for A vulnerability exists in the process of creating default IP blocks during device initialization for Cisco ASA Next-Generation Firewall Services that could allow an unauthenticated, remote attacker to send traffic to the local IP address of the device, bypassing any filters that are configured to deny local IP management traffic. The vulnerability is
nvd
CVE-2017-12277HIGHCVSS 8.8≤ 1.1.3v1.1.4+1 more2017-11-02
CVE-2017-12277 [HIGH] CWE-20 CVE-2017-12277: A vulnerability in the Smart Licensing Manager service of the Cisco Firepower 4100 Series Next-Gener A vulnerability in the Smart Licensing Manager service of the Cisco Firepower 4100 Series Next-Generation Firewall (NGFW) and Firepower 9300 Security Appliance could allow an authenticated, remote attacker to inject arbitrary commands that could be executed with root privileges. The vulnerability is due to insufficient input validation of certain Smart
nvd
CVE-2017-3883HIGHCVSS 8.6≤ 2.32017-10-19
CVE-2017-3883 [HIGH] CWE-770 CVE-2017-3883: A vulnerability in the authentication, authorization, and accounting (AAA) implementation of Cisco F A vulnerability in the authentication, authorization, and accounting (AAA) implementation of Cisco Firepower Extensible Operating System (FXOS) and NX-OS System Software could allow an unauthenticated, remote attacker to cause an affected device to reload. The vulnerability occurs because AAA processes prevent the NX-OS System Manager from receiving kee
nvd
CVE-2017-6597HIGHCVSS 7.8v2.0\(1.68\)2017-04-07
CVE-2017-6597 [HIGH] CWE-78 CVE-2017-6597: A vulnerability in the local-mgmt CLI command of the Cisco Unified Computing System (UCS) Manager, C A vulnerability in the local-mgmt CLI command of the Cisco Unified Computing System (UCS) Manager, Cisco Firepower 4100 Series Next-Generation Firewall (NGFW), and Cisco Firepower 9300 Security Appliance could allow an authenticated, local attacker to perform a command injection attack. More Information: CSCvb61394 CSCvb86816. Known Affected Releases: 2.
nvd
CVE-2017-6600HIGHCVSS 7.8v2.0\(1.68\)2017-04-07
CVE-2017-6600 [HIGH] CWE-78 CVE-2017-6600: A vulnerability in the CLI of the Cisco Unified Computing System (UCS) Manager, Cisco Firepower 4100 A vulnerability in the CLI of the Cisco Unified Computing System (UCS) Manager, Cisco Firepower 4100 Series Next-Generation Firewall (NGFW), and Cisco Firepower 9300 Security Appliance could allow an authenticated, local attacker to perform a command injection attack. More Information: CSCvb61351 CSCvb61637. Known Affected Releases: 2.0(1.68) 3.1(1k)A. K
nvd
CVE-2017-6601HIGHCVSS 7.1v2.0\(1.68\)2017-04-07
CVE-2017-6601 [HIGH] CWE-78 CVE-2017-6601: A vulnerability in the CLI of the Cisco Unified Computing System (UCS) Manager, Cisco Firepower 4100 A vulnerability in the CLI of the Cisco Unified Computing System (UCS) Manager, Cisco Firepower 4100 Series Next-Generation Firewall (NGFW), and Cisco Firepower 9300 Security Appliance could allow an authenticated, local attacker to perform a command injection attack. More Information: CSCvb61384 CSCvb86764. Known Affected Releases: 2.0(1.68) 3.1(1k)A. K
nvd
Cisco Firepower Extensible Operating System vulnerabilities | cvebase