cbcvebase.

Cisco Firepower Extensible Operating System vulnerabilities

52 known vulnerabilities affecting cisco/firepower_extensible_operating_system.

Total CVEs
52
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL2HIGH22MEDIUM28

Vulnerabilities

Page 2 of 3
CVE-2017-6600P3HIGHCVSS 7.8v2.0\(1.68\)2017-04-07
CVE-2017-6600 [HIGH] CWE-78 CVE-2017-6600: A vulnerability in the CLI of the Cisco Unified Computing System (UCS) Manager, Cisco Firepower 4100 A vulnerability in the CLI of the Cisco Unified Computing System (UCS) Manager, Cisco Firepower 4100 Series Next-Generation Firewall (NGFW), and Cisco Firepower 9300 Security Appliance could allow an authenticated, local attacker to perform a command injection attack. More Information: CSCvb61351 CSCvb61637. Known Affected Releases: 2.0(1.68) 3.1(1k)A. K
nvd
CVE-2015-6380P3MEDIUMCVSS 6.5v1.1\(1.160\)2015-11-24
CVE-2015-6380 [MEDIUM] CWE-78 CVE-2015-6380: An unspecified script in the web interface in Cisco Firepower Extensible Operating System 1.1(1.160) An unspecified script in the web interface in Cisco Firepower Extensible Operating System 1.1(1.160) on Firepower 9000 devices allows remote authenticated users to execute arbitrary OS commands via crafted parameters, aka Bug ID CSCux10622.
nvd
CVE-2021-34714P3HIGHCVSS 7.4≤ 8.4\(3.115\)≤ 7.0\(3\)i7\(9\)+3 more2021-09-23
CVE-2021-34714 [HIGH] CWE-20 CVE-2021-34714: A vulnerability in the Unidirectional Link Detection (UDLD) feature of Cisco FXOS Software, Cisco IO A vulnerability in the Unidirectional Link Detection (UDLD) feature of Cisco FXOS Software, Cisco IOS Software, Cisco IOS XE Software, Cisco IOS XR Software, and Cisco NX-OS Software could allow an unauthenticated, adjacent attacker to cause an affected device to reload. This vulnerability is due to improper input validation of the UDLD packets. An att
nvd
CVE-2015-6370P3HIGHCVSS 7.2v1.1\(1.160\)2015-11-19
CVE-2015-6370 [HIGH] CWE-78 CVE-2015-6370: The Management I/O (MIO) component in Cisco Firepower Extensible Operating System 1.1(1.160) on Fire The Management I/O (MIO) component in Cisco Firepower Extensible Operating System 1.1(1.160) on Firepower 9000 devices allows local users to execute arbitrary OS commands as root via crafted CLI input, aka Bug ID CSCux10578.
nvd
CVE-2019-12700P3MEDIUMCVSS 6.5≤ 2.2≥ 2.3, < 2.3.1.155+1 more2019-10-02
CVE-2019-12700 [MEDIUM] CWE-400 CVE-2019-12700: A vulnerability in the configuration of the Pluggable Authentication Module (PAM) used in Cisco Fire A vulnerability in the configuration of the Pluggable Authentication Module (PAM) used in Cisco Firepower Threat Defense (FTD) Software, Cisco Firepower Management Center (FMC) Software, and Cisco FXOS Software could allow an authenticated, remote attacker to cause a denial of service (DoS) condition. The vulnerability is due to improper resource ma
nvd
CVE-2019-1795P3MEDIUMCVSS 6.7fixed in 2.0.1.201≥ 2.1, < 2.2.2.54+2 more2019-05-15
CVE-2019-1795 [MEDIUM] CWE-77 CVE-2019-1795: A vulnerability in the CLI of Cisco FXOS Software and Cisco NX-OS Software could allow an authentica A vulnerability in the CLI of Cisco FXOS Software and Cisco NX-OS Software could allow an authenticated, local attacker to execute arbitrary commands on the underlying Linux operating system with the privilege level of root. The vulnerability is due to insufficient validation of arguments passed to a specific CLI command on the affected device. An atta
nvd
CVE-2019-1780P3MEDIUMCVSS 6.7fixed in 2.3.1.130≥ 2.4, < 2.4.1.1222019-05-16
CVE-2019-1780 [MEDIUM] CWE-77 CVE-2019-1780: A vulnerability in the CLI of Cisco FXOS Software and Cisco NX-OS Software could allow an authentica A vulnerability in the CLI of Cisco FXOS Software and Cisco NX-OS Software could allow an authenticated, local attacker with administrator credentials to execute arbitrary commands on the underlying operating system of an affected device with elevated privileges. The vulnerability is due to insufficient validation of arguments passed to certain CLI com
nvd
CVE-2020-3169P3MEDIUMCVSS 6.7≥ 2.2, < 2.2.2.97≥ 2.3, < 2.3.1.144+1 more2020-02-26
CVE-2020-3169 [MEDIUM] CWE-78 CVE-2020-3169: A vulnerability in the CLI of Cisco FXOS Software could allow an authenticated, local attacker to ex A vulnerability in the CLI of Cisco FXOS Software could allow an authenticated, local attacker to execute arbitrary commands on the underlying Linux operating system with a privilege level of root on an affected device. The vulnerability is due to insufficient validation of arguments passed to a specific CLI command on the affected device. An attacker
nvd
CVE-2022-20934P3MEDIUMCVSS 6.7v1.1.1.147v1.1.1.160+130 more2022-11-15
CVE-2022-20934 [MEDIUM] CWE-77 CVE-2022-20934: A vulnerability in the CLI of Cisco Firepower Threat Defense (FTD) Software and Cisco FXOS Software A vulnerability in the CLI of Cisco Firepower Threat Defense (FTD) Software and Cisco FXOS Software could allow an authenticated, local attacker to execute arbitrary commands on the underlying operating system as root. This vulnerability is due to improper input validation for specific CLI commands. An attacker could exploit this vulnerability by inje
nvd
CVE-2019-1779P4MEDIUMCVSS 6.7fixed in 2.4.1.1012019-05-15
CVE-2019-1779 [MEDIUM] CWE-77 CVE-2019-1779: A vulnerability in the CLI of Cisco FXOS Software and Cisco NX-OS Software could allow an authentica A vulnerability in the CLI of Cisco FXOS Software and Cisco NX-OS Software could allow an authenticated, local attacker to execute arbitrary commands on the underlying operating system of an affected device with elevated privileges. The vulnerability is due to insufficient validation of arguments passed to certain CLI commands. An attacker could exploi
nvd
CVE-2020-3457P4MEDIUMCVSS 6.7≥ 2.4, < 2.4.1.266≥ 2.6, < 2.6.1.204+2 more2020-10-21
CVE-2020-3457 [MEDIUM] CWE-78 CVE-2020-3457: A vulnerability in the CLI of Cisco FXOS Software could allow an authenticated, local attacker to in A vulnerability in the CLI of Cisco FXOS Software could allow an authenticated, local attacker to inject arbitrary commands that are executed with root privileges. The vulnerability is due to insufficient input validation of commands supplied by the user. An attacker could exploit this vulnerability by authenticating to a device and submitting crafted
nvd
CVE-2017-6601P4HIGHCVSS 7.1v2.0\(1.68\)2017-04-07
CVE-2017-6601 [HIGH] CWE-78 CVE-2017-6601: A vulnerability in the CLI of the Cisco Unified Computing System (UCS) Manager, Cisco Firepower 4100 A vulnerability in the CLI of the Cisco Unified Computing System (UCS) Manager, Cisco Firepower 4100 Series Next-Generation Firewall (NGFW), and Cisco Firepower 9300 Security Appliance could allow an authenticated, local attacker to perform a command injection attack. More Information: CSCvb61384 CSCvb86764. Known Affected Releases: 2.0(1.68) 3.1(1k)A. K
nvd
CVE-2020-3545P4MEDIUMCVSS 6.7≤ 2.3.1.582020-09-04
CVE-2020-3545 [MEDIUM] CWE-119 CVE-2020-3545: A vulnerability in Cisco FXOS Software could allow an authenticated, local attacker with administrat A vulnerability in Cisco FXOS Software could allow an authenticated, local attacker with administrative credentials to cause a buffer overflow condition. The vulnerability is due to incorrect bounds checking of values that are parsed from a specific file. An attacker could exploit this vulnerability by supplying a crafted file that, when it is process
nvd
CVE-2020-3166P4MEDIUMCVSS 6.7fixed in 2.2.2.97≥ 2.3, < 2.3.1.155+2 more2020-02-26
CVE-2020-3166 [MEDIUM] CWE-20 CVE-2020-3166: A vulnerability in the CLI of Cisco FXOS Software could allow an authenticated, local attacker to re A vulnerability in the CLI of Cisco FXOS Software could allow an authenticated, local attacker to read or write arbitrary files on the underlying operating system (OS). The vulnerability is due to insufficient input validation. An attacker could exploit this vulnerability by including crafted arguments to a specific CLI command. A successful exploit co
nvd
CVE-2018-0294P4MEDIUMCVSS 6.7≥ 2.1.1, < 2.1.1.86≥ 2.2, < 2.2.2.172018-06-20
CVE-2018-0294 [MEDIUM] CWE-264 CVE-2018-0294: A vulnerability in the write-erase feature of Cisco FXOS Software and Cisco NX-OS Software could all A vulnerability in the write-erase feature of Cisco FXOS Software and Cisco NX-OS Software could allow an authenticated, local attacker to configure an unauthorized administrator account for an affected device. The vulnerability exists because the affected software does not properly delete sensitive files when certain CLI commands are used to clear th
nvd
CVE-2017-6598P4MEDIUMCVSS 6.7v2.0\(1.68\)2017-04-07
CVE-2017-6598 [MEDIUM] CWE-862 CVE-2017-6598: A vulnerability in the debug plug-in functionality of the Cisco Unified Computing System (UCS) Manag A vulnerability in the debug plug-in functionality of the Cisco Unified Computing System (UCS) Manager, Cisco Firepower 4100 Series Next-Generation Firewall (NGFW), and Cisco Firepower 9300 Security Appliance could allow an authenticated, local attacker to execute arbitrary commands, aka Privilege Escalation. More Information: CSCvb86725 CSCvb86797. K
nvd
CVE-2015-6368P4MEDIUMCVSS 5.0v1.1\(1.160\)2015-11-19
CVE-2015-6368 [MEDIUM] CWE-200 CVE-2015-6368: Cisco Firepower Extensible Operating System 1.1(1.160) on Firepower 9000 devices allows remote attac Cisco Firepower Extensible Operating System 1.1(1.160) on Firepower 9000 devices allows remote attackers to read files via a crafted HTTP request, aka Bug ID CSCux10608.
nvd
CVE-2020-3120P4MEDIUMCVSS 6.5≤ 2.3.1.173≥ 2.6, < 2.6.1.187+1 more2020-02-05
CVE-2020-3120 [MEDIUM] CWE-190 CVE-2020-3120: A vulnerability in the Cisco Discovery Protocol implementation for Cisco FXOS Software, Cisco IOS XR A vulnerability in the Cisco Discovery Protocol implementation for Cisco FXOS Software, Cisco IOS XR Software, and Cisco NX-OS Software could allow an unauthenticated, adjacent attacker to cause a reload of an affected device, resulting in a denial of service (DoS) condition. The vulnerability is due to a missing check when the affected software proce
nvd
CVE-2015-6373P4MEDIUMCVSS 6.8v1.1\(1.160\)2015-11-18
CVE-2015-6373 [MEDIUM] CWE-352 CVE-2015-6373: Cross-site request forgery (CSRF) vulnerability in Cisco Firepower Extensible Operating System 1.1(1 Cross-site request forgery (CSRF) vulnerability in Cisco Firepower Extensible Operating System 1.1(1.160) on Firepower 9000 devices allows remote attackers to hijack the authentication of arbitrary users, aka Bug ID CSCux10611.
nvd
CVE-2018-0331P4MEDIUMCVSS 6.5≥ 1.1, < 2.0.1.153≥ 2.1.1, < 2.1.1.86+1 more2018-06-21
CVE-2018-0331 [MEDIUM] CWE-399 CVE-2018-0331: A vulnerability in the Cisco Discovery Protocol (formerly known as CDP) subsystem of devices running A vulnerability in the Cisco Discovery Protocol (formerly known as CDP) subsystem of devices running, or based on, Cisco NX-OS Software contain a vulnerability that could allow an unauthenticated, adjacent attacker to create a denial of service (DoS) condition. The vulnerability is due to a failure to properly validate certain fields within a Cisco Di
nvd
Cisco Firepower Extensible Operating System vulnerabilities | cvebase