CVE-2026-20017: Cisco Secure FTD Software Authenticated Command Injection Vulnerability
A vulnerability in the CLI of Cisco Secure FTD Software could allow an authenticated, local attacker to execute arbitrary commands on the underlying operating system as root. To exploit this vulnerability, the attacker must have valid administrative credentials on an affected device. This vulnerability is due to insufficient input validation of user-supplied command arguments. An attacker could exploit this vulnerability by submitting crafted input for a specific CLI command. A successful exploit could allow the attacker to execute commands on the underlying operating system as root.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-20017?
CVE-2026-20017 is classified as a critical vulnerability due to its potential to allow authenticated users to execute arbitrary commands as root.
How do I fix CVE-2026-20017?
To fix CVE-2026-20017, update the Cisco Secure FTD Software to the latest available version provided by Cisco.
Who is affected by CVE-2026-20017?
CVE-2026-20017 affects users of Cisco Secure FTD Software that allow authenticated local access.
What is the impact of exploiting CVE-2026-20017?
Exploiting CVE-2026-20017 allows attackers to run arbitrary commands on the system, potentially leading to a full system compromise.
Is authentication required to exploit CVE-2026-20017?
Yes, an attacker must be an authenticated local user to exploit CVE-2026-20017.