Cisco FXOS Software Command Injection Vulnerability
Published Oct 21, 2020
6.7
MEDIUMCVSS 3.1
EPSS 0.40%
Description
A vulnerability in the CLI of Cisco FXOS Software could allow an authenticated, local attacker to inject arbitrary commands that are executed with root privileges. The vulnerability is due to insufficient input validation of commands supplied by the user. An attacker could exploit this vulnerability by authenticating to a device and submitting crafted input to the affected command. A successful exploit could allow the attacker to execute commands on the underlying operating system with root privileges.
Affected products
-
Affected
- n/a
Default status is the baseline for the product. Each version can override it (patched versions can be marked unaffected).
| Vendor | Product | Default status | Versions |
|---|---|---|---|
| Cisco | Cisco Adaptive Security Appliance (ASA) Software | unknown | Affected
|
Configuration 1
- ≥ 2.4 · < 2.4.1.266
- ≥ 2.6 · < 2.6.1.204
- ≥ 2.7 · < 2.7.1.131
- ≥ 2.8 · < 2.8.1.125
Running on/with
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
Configuration 2
- ≥ 9.8 · < 9.8.4.29
- ≥ 9.9 · < 9.9.2.80
- ≥ 9.10 · < 9.10.1.40
- ≥ 9.12 · < 9.12.4.3
- ≥ 9.13 · < 9.13.1.13
Running on/with
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
Configuration 3
- ≥ 6.2.2 · < 6.3.0.6
- ≥ 6.4.0 · < 6.4.0.9
- ≥ 6.5.0 · < 6.5.0.5
Running on/with
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
References (2)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2020-24728 Advisory
- https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-fxos-cmdinj-pqZvmXCr vendor-advisoryx_refsource_CISCOPatchVendor Advisory
| Link | Providers | Tags |
|---|---|---|
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2020-24728 | Advisory | |
| https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-fxos-cmdinj-pqZvmXCr | vendor-advisoryx_refsource_CISCOPatchVendor Advisory |
Change history (0)
No recorded changes yet.
CVE.org / MITRE
CISA Vulnrichment
Red Hat
No data
GitHub
No data