Cisco Firepower Threat Defense Software Multi-instance Container Escape Vulnerabilities
Summary
| CVE | CVE-2019-12674 |
|---|---|
| State | PUBLISHED |
| Assigner | cisco |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2019-10-02 19:15:12 UTC |
| Updated | 2026-08-11 19:37:30 UTC |
| Description | Multiple vulnerabilities in the multi-instance feature of Cisco Firepower Threat Defense (FTD) Software could allow an authenticated, local attacker to escape the container for their FTD instance and execute commands with root privileges in the host namespace. These vulnerabilities are due to insufficient protections on the underlying filesystem. An attacker could exploit these vulnerabilities by modifying critical files on the underlying filesystem. A successful exploit could allow the attacker to execute commands with root privileges within the host namespace. This could allow the attacker to impact other running FTD instances. |
Risk And Classification
Primary CVSS: v3.1 8.2 HIGH from [email protected]
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
EPSS: 0.004250000 probability, percentile 0.352130000 (date 2026-08-12)
Problem Types: CWE-216 | CWE-116 | CWE-216 CWE-216
| Version | Source | Type | Score | Severity | Vector |
|---|---|---|---|---|---|
| 3.1 | [email protected] | Primary | 8.2 | HIGH | CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H |
| 3.0 | [email protected] | Secondary | 8.2 | HIGH | CVSS:3.0/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H |
| 3.0 | CNA | DECLARED | 8.2 | HIGH | CVSS:3.0/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H |
| 2.0 | [email protected] | Primary | 7.2 | AV:L/AC:L/Au:N/C:C/I:C/A:C |
CVSS v3.1 Breakdown
Attack Vector
LocalAttack Complexity
LowPrivileges Required
HighUser Interaction
NoneScope
ChangedConfidentiality
HighIntegrity
HighAvailability
HighCVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
CVSS v3.0 Breakdown
Attack Vector
LocalAttack Complexity
LowPrivileges Required
HighUser Interaction
NoneScope
ChangedConfidentiality
HighIntegrity
HighAvailability
HighCVSS:3.0/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
CVSS v2.0 Breakdown
Access Vector
LocalAccess Complexity
LowAuthentication
NoneConfidentiality
CompleteIntegrity
CompleteAvailability
CompleteAV:L/AC:L/Au:N/C:C/I:C/A:C
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Hardware | Cisco | Firepower 4110 | - | All | All | All |
| Operating System | Cisco | Firepower 4110 Firmware | - | All | All | All |
| Hardware | Cisco | Firepower 4115 | - | All | All | All |
| Operating System | Cisco | Firepower 4115 Firmware | - | All | All | All |
| Hardware | Cisco | Firepower 4120 | - | All | All | All |
| Operating System | Cisco | Firepower 4120 Firmware | - | All | All | All |
| Hardware | Cisco | Firepower 4125 | - | All | All | All |
| Operating System | Cisco | Firepower 4125 Firmware | - | All | All | All |
| Hardware | Cisco | Firepower 4140 | - | All | All | All |
| Operating System | Cisco | Firepower 4140 Firmware | - | All | All | All |
| Hardware | Cisco | Firepower 4145 | - | All | All | All |
| Operating System | Cisco | Firepower 4145 Firmware | - | All | All | All |
| Hardware | Cisco | Firepower 4150 | - | All | All | All |
| Operating System | Cisco | Firepower 4150 Firmware | - | All | All | All |
| Hardware | Cisco | Firepower 9300 | - | All | All | All |
| Operating System | Cisco | Firepower 9300 Firmware | - | All | All | All |
| Application | Cisco | Secure Firewall Threat Defense | All | All | All | All |
Vendor Declared Affected Products
| Source | Vendor | Product | Version | Platforms |
|---|---|---|---|---|
| CNA | Cisco | Cisco Firepower Threat Defense Software | affected unspecified n/a custom | Not specified |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Cisco Firepower Threat Defense Software Multi-instance Container Escape Vulnerabilities | af854a3a-2127-422b-91ae-364da2661108 | tools.cisco.com | Vendor Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
Additional Advisory Data
Exploits
CNA: The Cisco Product Security Incident Response Team (PSIRT) is not aware of any public announcements or malicious use of the vulnerabilities that are described in this advisory.
There are currently no legacy QID mappings associated with this CVE.