CVE-2020-3169
26.02.2020, 17:15
A vulnerability in the CLI of Cisco FXOS Software could allow an authenticated, local attacker to execute arbitrary commands on the underlying Linux operating system with a privilege level of root on an affected device. The vulnerability is due to insufficient validation of arguments passed to a specific CLI command on the affected device. An attacker could exploit this vulnerability by including malicious input as the argument of an affected command. A successful exploit could allow the attacker to execute arbitrary commands on the underlying Linux operating system with root privileges. An attacker would need valid administrator credentials to exploit this vulnerability.
| Vendor | Product | Version |
|---|---|---|
| cisco | firepower_extensible_operating_system | 2.2 ≤ 𝑥 < 2.2.2.97 |
| cisco | firepower_extensible_operating_system | 2.3 ≤ 𝑥 < 2.3.1.144 |
| cisco | firepower_extensible_operating_system | 2.4 ≤ 𝑥 < 2.4.1.234 |
𝑥
= Vulnerable software versions