cbcvebase.

Cisco Firepower Extensible Operating System vulnerabilities

52 known vulnerabilities affecting cisco/firepower_extensible_operating_system.

Total CVEs
52
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL2HIGH22MEDIUM28

Vulnerabilities

Page 3 of 3
CVE-2017-12299P4MEDIUMCVSS 5.3v2.2\(1.58\)2017-11-16
CVE-2017-12299 [MEDIUM] CWE-20 CVE-2017-12299: A vulnerability exists in the process of creating default IP blocks during device initialization for A vulnerability exists in the process of creating default IP blocks during device initialization for Cisco ASA Next-Generation Firewall Services that could allow an unauthenticated, remote attacker to send traffic to the local IP address of the device, bypassing any filters that are configured to deny local IP management traffic. The vulnerability is
nvd
CVE-2019-1734P4MEDIUMCVSS 5.5fixed in 2.2.2.91≥ 2.3, < 2.3.1.111+1 more2019-11-05
CVE-2019-1734 [MEDIUM] CWE-200 CVE-2019-1734: A vulnerability in the implementation of a CLI diagnostic command in Cisco FXOS Software and Cisco N A vulnerability in the implementation of a CLI diagnostic command in Cisco FXOS Software and Cisco NX-OS Software could allow an authenticated, local attacker to view sensitive system files that should be restricted. The attacker could use this information to conduct additional reconnaissance attacks. The vulnerability is due to incomplete role-based
nvd
CVE-2024-20294P4MEDIUMCVSS 6.6v2.2.1.63v2.2.1.66+97 more2024-02-29
CVE-2024-20294 [MEDIUM] CWE-805 CVE-2024-20294: A vulnerability in the Link Layer Discovery Protocol (LLDP) feature of Cisco FXOS Software and Cisco A vulnerability in the Link Layer Discovery Protocol (LLDP) feature of Cisco FXOS Software and Cisco NX-OS Software could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to improper handling of specific fields in an LLDP frame. An attacker could exploit this vu
nvd
CVE-2022-20625P4MEDIUMCVSS 4.3fixed in 2.3.1.219≥ 2.4, < 2.9.1.158+1 more2022-02-23
CVE-2022-20625 [MEDIUM] CWE-399 CVE-2022-20625: A vulnerability in the Cisco Discovery Protocol service of Cisco FXOS Software and Cisco NX-OS Softw A vulnerability in the Cisco Discovery Protocol service of Cisco FXOS Software and Cisco NX-OS Software could allow an unauthenticated, adjacent attacker to cause the service to restart, resulting in a denial of service (DoS) condition. This vulnerability is due to improper handling of Cisco Discovery Protocol messages that are processed by the Cisc
nvd
CVE-2015-4287P4MEDIUMCVSS 5.0v1.1\(1.86\)2015-07-29
CVE-2015-4287 [MEDIUM] CWE-264 CVE-2015-4287: Cisco Firepower Extensible Operating System 1.1(1.86) on Firepower 9000 devices allows remote attack Cisco Firepower Extensible Operating System 1.1(1.86) on Firepower 9000 devices allows remote attackers to bypass intended access restrictions and obtain sensitive device information by visiting an unspecified web page, aka Bug ID CSCuu82230.
nvd
CVE-2018-0395P4MEDIUMCVSS 5.3vr2312018-10-17
CVE-2018-0395 [MEDIUM] CWE-20 CVE-2018-0395: A vulnerability in the Link Layer Discovery Protocol (LLDP) implementation for Cisco FXOS Software a A vulnerability in the Link Layer Discovery Protocol (LLDP) implementation for Cisco FXOS Software and Cisco NX-OS Software could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) condition when the device unexpectedly reloads. The vulnerability is due to improper input validation of certain type, length, value (TLV) fields
nvd
CVE-2015-6371P4MEDIUMCVSS 4.0v1.1\(1.160\)2015-11-19
CVE-2015-6371 [MEDIUM] CWE-200 CVE-2015-6371: Cisco Firepower Extensible Operating System 1.1(1.160) on Firepower 9000 devices allows remote authe Cisco Firepower Extensible Operating System 1.1(1.160) on Firepower 9000 devices allows remote authenticated users to read arbitrary files via crafted parameters to unspecified scripts, aka Bug ID CSCux10621.
nvd
CVE-2015-6369P4MEDIUMCVSS 4.9v1.1\(1.160\)2015-11-19
CVE-2015-6369 [MEDIUM] CWE-20 CVE-2015-6369: The USB driver in Cisco Firepower Extensible Operating System 1.1(1.160) on Firepower 9000 devices a The USB driver in Cisco Firepower Extensible Operating System 1.1(1.160) on Firepower 9000 devices allows physically proximate attackers to cause a denial of service via a crafted USB device that triggers invalid USB commands, aka Bug ID CSCux10531.
nvd
CVE-2017-6602P4MEDIUMCVSS 4.4v2.0\(1.68\)2017-04-07
CVE-2017-6602 [MEDIUM] CWE-78 CVE-2017-6602: A vulnerability in the CLI of Cisco Unified Computing System (UCS) Manager, Cisco Firepower 4100 Ser A vulnerability in the CLI of Cisco Unified Computing System (UCS) Manager, Cisco Firepower 4100 Series Next-Generation Firewall (NGFW), and Cisco Firepower 9300 Security Appliance could allow an authenticated, local attacker to perform a command injection attack. More Information: CSCvb66189 CSCvb86775. Known Affected Releases: 2.0(1.68) 3.1(1k)A. Kno
nvd
CVE-2019-1600P4MEDIUMCVSS 4.4≥ 1.1, < 2.2.2.91≥ 2.3, < 2.3.1.1102019-03-07
CVE-2019-1600 [MEDIUM] CWE-264 CVE-2019-1600: A vulnerability in the file system permissions of Cisco FXOS Software and Cisco NX-OS Software could A vulnerability in the file system permissions of Cisco FXOS Software and Cisco NX-OS Software could allow an authenticated, local attacker to access sensitive information that is stored in the file system of an affected system. The vulnerability is due to improper implementation of file system permissions. An attacker could exploit this vulnerability
nvd
CVE-2015-6372P4MEDIUMCVSS 4.3v1.1\(1.160\)2015-11-18
CVE-2015-6372 [MEDIUM] CWE-79 CVE-2015-6372: Cross-site scripting (XSS) vulnerability in the web-based management interface in Cisco Firepower Ex Cross-site scripting (XSS) vulnerability in the web-based management interface in Cisco Firepower Extensible Operating System 1.1(1.160) on Firepower 9000 devices allows remote attackers to inject arbitrary web script or HTML via a crafted value, aka Bug ID CSCux10614.
nvd
CVE-2015-6374P4MEDIUMCVSS 4.3v1.1\(1.160\)2015-11-19
CVE-2015-6374 [MEDIUM] CWE-20 CVE-2015-6374: The web interface in Cisco Firepower Extensible Operating System 1.1(1.160) on Firepower 9000 device The web interface in Cisco Firepower Extensible Operating System 1.1(1.160) on Firepower 9000 devices does not properly restrict use of IFRAME elements, which makes it easier for remote attackers to conduct clickjacking attacks and unspecified other attacks via a crafted web site, aka Bug ID CSCux10604.
nvd
Cisco Firepower Extensible Operating System vulnerabilities | cvebase