CVE-2019-12689: Cisco Firepower Management Center Remote Code Execution Vulnerability
A vulnerability in the web-based management interface of Cisco Firepower Management Center (FMC) Software could allow an authenticated, remote attacker to execute arbitrary code on the underlying operating system of an affected device. The vulnerability is due to insufficient input validation. An attacker could exploit this vulnerability by sending malicious commands to the web-based management interface of an affected device. A successful exploit could allow the attacker to execute arbitrary code on the underlying operating system of the affected device.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2019-12689?
CVE-2019-12689 has a high severity rating due to its potential for arbitrary code execution on vulnerable Cisco devices.
How do I fix CVE-2019-12689?
To mitigate CVE-2019-12689, upgrade the Cisco Firepower Management Center Software to version 6.2.2.2 or later.
What devices are affected by CVE-2019-12689?
CVE-2019-12689 affects Cisco Secure Firewall Management Center versions prior to 6.2.2.2.
Who can exploit CVE-2019-12689?
An authenticated remote attacker can exploit CVE-2019-12689 to execute arbitrary code on the affected system.
What type of vulnerability is CVE-2019-12689?
CVE-2019-12689 is classified as a remote code execution vulnerability in the web-based management interface of the affected Cisco software.