CVE-2019-12699: Cisco FXOS Software and Firepower Threat Defense Software Command Injection Vulnerabilities
Multiple vulnerabilities in the CLI of Cisco FXOS Software and Cisco Firepower Threat Defense (FTD) Software could allow an authenticated, local attacker to execute commands on the underlying operating system (OS) with root privileges. These vulnerabilities are due to insufficient input validation. An attacker could exploit these vulnerabilities by including crafted arguments to specific CLI commands. A successful exploit could allow the attacker to execute commands on the underlying OS with root privileges.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2019-12699?
CVE-2019-12699 is a vulnerability in the CLI of Cisco FXOS Software and Cisco Firepower Threat Defense (FTD) Software that could allow an authenticated, local attacker to execute commands on the underlying operating system with root privileges.
How severe is CVE-2019-12699?
CVE-2019-12699 has a severity rating of 7.8 (high).
How can an attacker exploit CVE-2019-12699?
An attacker can exploit CVE-2019-12699 by executing commands on the underlying operating system through the CLI.
What is the affected software for CVE-2019-12699?
The affected software for CVE-2019-12699 includes Cisco Firepower 9300 Firmware versions 2.4(1.214), 2.4(1.216), and 2.4(2.54), as well as Cisco Firepower Threat Defense versions up to 6.1.0, 6.2.0 up to 6.2.3.14, and 6.3.0 up to 6.3.0.3.
Is Cisco Firepower 9300 vulnerable to CVE-2019-12699?
No, Cisco Firepower 9300 is not vulnerable to CVE-2019-12699.