CVE-2019-12694: Cisco Firepower Threat Defense Software Command Injection Vulnerability
A vulnerability in the command line interface (CLI) of Cisco Firepower Threat Defense (FTD) Software could allow an authenticated, local attacker with administrative privileges to execute commands on the underlying operating system with root privileges. The vulnerability is due to insufficient input validation. An attacker could exploit this vulnerability by executing a specific CLI command that includes crafted arguments. A successful exploit could allow the attacker to execute commands on the underlying OS with root privileges.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2019-12694?
CVE-2019-12694 has been classified as a critical severity vulnerability due to its potential for remote code execution with root privileges.
How do I fix CVE-2019-12694?
To fix CVE-2019-12694, you should update your Cisco Firepower Threat Defense software to the latest version available.
Who is affected by CVE-2019-12694?
CVE-2019-12694 affects Cisco Firepower Threat Defense software versions prior to 6.3.0.5 and between 6.4.0 and 6.4.0.4.
What type of attack does CVE-2019-12694 allow?
CVE-2019-12694 allows an authenticated local attacker with administrative privileges to execute arbitrary commands on the system.
Is CVE-2019-12694 related to the command line interface?
Yes, CVE-2019-12694 arises from a vulnerability in the command line interface (CLI) of Cisco Firepower Threat Defense software.