CVE-2021-34752

EUVD-2021-21402
A vulnerability in the CLI of Cisco FTD Software could allow an authenticated, local attacker with administrative privileges to execute arbitrary commands with root privileges on the underlying operating system of an affected device. 

This vulnerability is due to insufficient validation of user-supplied command arguments. An attacker could exploit this vulnerability by submitting crafted input to the affected commands. A successful exploit could allow the attacker to execute commands with root privileges on the underlying operating system.
Cisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
6.7 MEDIUM
LOCAL
LOW
HIGH
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: Unknown
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
VendorProductVersionSource
ciscofirepower_threat_defense_software
𝑥
< 6.4.0.13
ADP
ciscofirepower_threat_defense_software
6.5.0 ≤
𝑥
< 6.6.5
ADP
ciscofirepower_threat_defense_software
6.7.0 ≤
𝑥
< 6.7.0.3
ADP
ciscofirepower_threat_defense_software
7.0.0 ≤
𝑥
< 7.0.1
ADP