CVE-2019-12699
Published on: 10/02/2019 12:00:00 AM UTC
Last Modified on: 03/23/2021 11:27:41 PM UTC
CVE-2019-12699 - advisory for cisco-sa-20191002-fxos-cmd-inject
Source: Mitre Source: NIST CVE.ORG Print: PDF
Certain versions of Firepower 1000 from Cisco contain the following vulnerability:
Multiple vulnerabilities in the CLI of Cisco FXOS Software and Cisco Firepower Threat Defense (FTD) Software could allow an authenticated, local attacker to execute commands on the underlying operating system (OS) with root privileges. These vulnerabilities are due to insufficient input validation. An attacker could exploit these vulnerabilities by including crafted arguments to specific CLI commands. A successful exploit could allow the attacker to execute commands on the underlying OS with root privileges.
- CVE-2019-12699 has been assigned by
[email protected] to track the vulnerability - currently rated as HIGH severity.
- The Cisco Product Security Incident Response Team (PSIRT) is not aware of any public announcements or malicious use of the vulnerabilities that are described in this advisory.
- Affected Vendor/Software:
Cisco - Cisco Firepower Extensible Operating System (FXOS) version n/a
CVSS3 Score: 7.8 - HIGH
Attack Vector ⓘ |
Attack Complexity |
Privileges Required |
User Interaction |
---|---|---|---|
LOCAL | LOW | LOW | NONE |
Scope | Confidentiality Impact |
Integrity Impact |
Availability Impact |
UNCHANGED | HIGH | HIGH | HIGH |
CVSS2 Score: 7.2 - HIGH
Access Vector ⓘ |
Access Complexity |
Authentication |
---|---|---|
LOCAL | LOW | NONE |
Confidentiality Impact |
Integrity Impact |
Availability Impact |
COMPLETE | COMPLETE | COMPLETE |
CVE References
Description | Tags ⓘ | Link |
---|---|---|
Cisco FXOS Software and Firepower Threat Defense Software Command Injection Vulnerabilities | Vendor Advisory tools.cisco.com text/html |
![]() |
There are currently no QIDs associated with this CVE
Known Affected Configurations (CPE V2.3)
Type | Vendor | Product | Version | Update | Edition | Language |
---|---|---|---|---|---|---|
Hardware
| Cisco | Firepower 1000 | - | All | All | All |
Hardware
| Cisco | Firepower 1000 | - | All | All | All |
Hardware
| Cisco | Firepower 2100 | - | All | All | All |
Hardware
| Cisco | Firepower 2100 | - | All | All | All |
Hardware
| Cisco | Firepower 4100 | - | All | All | All |
Hardware
| Cisco | Firepower 4100 | - | All | All | All |
Hardware
| Cisco | Firepower 9300 | All | All | All | All |
Hardware
| Cisco | Firepower 9300 | - | All | All | All |
Hardware
| Cisco | Firepower 9300 | All | All | All | All |
Hardware
| Cisco | Firepower 9300 | - | All | All | All |
Operating System | Cisco | Firepower 9300 Firmware | 2.4(1.214) | All | All | All |
Operating System | Cisco | Firepower 9300 Firmware | 2.4(1.216) | All | All | All |
Operating System | Cisco | Firepower 9300 Firmware | 2.4(2.54) | All | All | All |
Operating System | Cisco | Firepower 9300 Firmware | 2.4\(1.214\) | All | All | All |
Operating System | Cisco | Firepower 9300 Firmware | 2.4\(1.216\) | All | All | All |
Operating System | Cisco | Firepower 9300 Firmware | 2.4\(2.54\) | All | All | All |
Operating System | Cisco | Firepower 9300 Firmware | r241 | All | All | All |
Operating System | Cisco | Firepower 9300 Firmware | 2.4\(1.214\) | All | All | All |
Operating System | Cisco | Firepower 9300 Firmware | 2.4\(1.216\) | All | All | All |
Operating System | Cisco | Firepower 9300 Firmware | 2.4\(2.54\) | All | All | All |
Operating System | Cisco | Firepower 9300 Firmware | r241 | All | All | All |
Application | Cisco | Firepower Threat Defense | All | All | All | All |
Application | Cisco | Firepower Threat Defense | All | All | All | All |
Application | Cisco | Firepower Threat Defense | All | All | All | All |
Operating System | Cisco | Fxos | All | All | All | All |
Operating System | Cisco | Fxos | All | All | All | All |
- cpe:2.3:h:cisco:firepower_1000:-:*:*:*:*:*:*:*:
- cpe:2.3:h:cisco:firepower_1000:-:*:*:*:*:*:*:*:
- cpe:2.3:h:cisco:firepower_2100:-:*:*:*:*:*:*:*:
- cpe:2.3:h:cisco:firepower_2100:-:*:*:*:*:*:*:*:
- cpe:2.3:h:cisco:firepower_4100:-:*:*:*:*:*:*:*:
- cpe:2.3:h:cisco:firepower_4100:-:*:*:*:*:*:*:*:
- cpe:2.3:h:cisco:firepower_9300:*:*:*:*:*:*:*:*:
- cpe:2.3:h:cisco:firepower_9300:-:*:*:*:*:*:*:*:
- cpe:2.3:h:cisco:firepower_9300:*:*:*:*:*:*:*:*:
- cpe:2.3:h:cisco:firepower_9300:-:*:*:*:*:*:*:*:
- cpe:2.3:o:cisco:firepower_9300_firmware:2.4(1.214):*:*:*:*:*:*:*:
- cpe:2.3:o:cisco:firepower_9300_firmware:2.4(1.216):*:*:*:*:*:*:*:
- cpe:2.3:o:cisco:firepower_9300_firmware:2.4(2.54):*:*:*:*:*:*:*:
- cpe:2.3:o:cisco:firepower_9300_firmware:2.4\(1.214\):*:*:*:*:*:*:*:
- cpe:2.3:o:cisco:firepower_9300_firmware:2.4\(1.216\):*:*:*:*:*:*:*:
- cpe:2.3:o:cisco:firepower_9300_firmware:2.4\(2.54\):*:*:*:*:*:*:*:
- cpe:2.3:o:cisco:firepower_9300_firmware:r241:*:*:*:*:*:*:*:
- cpe:2.3:o:cisco:firepower_9300_firmware:2.4\(1.214\):*:*:*:*:*:*:*:
- cpe:2.3:o:cisco:firepower_9300_firmware:2.4\(1.216\):*:*:*:*:*:*:*:
- cpe:2.3:o:cisco:firepower_9300_firmware:2.4\(2.54\):*:*:*:*:*:*:*:
- cpe:2.3:o:cisco:firepower_9300_firmware:r241:*:*:*:*:*:*:*:
- cpe:2.3:a:cisco:firepower_threat_defense:*:*:*:*:*:*:*:*:
- cpe:2.3:a:cisco:firepower_threat_defense:*:*:*:*:*:*:*:*:
- cpe:2.3:a:cisco:firepower_threat_defense:*:*:*:*:*:*:*:*:
- cpe:2.3:o:cisco:fxos:*:*:*:*:*:*:*:*:
- cpe:2.3:o:cisco:fxos:*:*:*:*:*:*:*:*:
No vendor comments have been submitted for this CVE