CVE-2021-34755
Published on: 10/27/2021 12:00:00 AM UTC
Last Modified on: 10/27/2022 04:44:00 PM UTC
CVE-2021-34755 - advisory for cisco-sa-ftd-cmdinject-FmzsLN8
Source: Mitre Source: NIST CVE.ORG Print: PDF
Certain versions of Firepower Management Center Virtual Appliance from Cisco contain the following vulnerability:
Multiple vulnerabilities in the CLI of Cisco Firepower Threat Defense (FTD) Software could allow an authenticated, local attacker to execute arbitrary commands with root privileges. For more information about these vulnerabilities, see the Details section of this advisory.
- CVE-2021-34755 has been assigned by
[email protected] to track the vulnerability - currently rated as HIGH severity.
- The Cisco PSIRT is not aware of any public announcements or malicious use of the vulnerability that is described in this advisory.
- Affected Vendor/Software:
Cisco - Cisco Firepower Threat Defense Software version n/a
CVSS3 Score: 7.8 - HIGH
Attack Vector ⓘ |
Attack Complexity |
Privileges Required |
User Interaction |
---|---|---|---|
LOCAL | LOW | LOW | NONE |
Scope | Confidentiality Impact |
Integrity Impact |
Availability Impact |
UNCHANGED | HIGH | HIGH | HIGH |
CVSS2 Score: 7.2 - HIGH
Access Vector ⓘ |
Access Complexity |
Authentication |
---|---|---|
LOCAL | LOW | NONE |
Confidentiality Impact |
Integrity Impact |
Availability Impact |
COMPLETE | COMPLETE | COMPLETE |
CVE References
Description | Tags ⓘ | Link |
---|---|---|
Cisco Firepower Threat Defense Software Command Injection Vulnerabilities | tools.cisco.com text/html |
![]() |
There are currently no QIDs associated with this CVE
Exploit/POC from Github
This repository contains a collection of data files on known Common Vulnerabilities and Exposures (CVEs). Each file i…
Known Affected Configurations (CPE V2.3)
- cpe:2.3:a:cisco:firepower_management_center_virtual_appliance:6.1.0:*:*:*:*:*:*:*:
- cpe:2.3:a:cisco:firepower_management_center_virtual_appliance:6.2.0:*:*:*:*:*:*:*:
- cpe:2.3:a:cisco:firepower_management_center_virtual_appliance:6.2.3:*:*:*:*:*:*:*:
- cpe:2.3:a:cisco:firepower_management_center_virtual_appliance:6.3.0:*:*:*:*:*:*:*:
- cpe:2.3:a:cisco:firepower_management_center_virtual_appliance:6.4.0:*:*:*:*:*:*:*:
- cpe:2.3:a:cisco:firepower_management_center_virtual_appliance:6.4.0.11:*:*:*:*:*:*:*:
- cpe:2.3:a:cisco:firepower_management_center_virtual_appliance:6.5.0:*:*:*:*:*:*:*:
- cpe:2.3:a:cisco:firepower_management_center_virtual_appliance:6.6.0:*:*:*:*:*:*:*:
- cpe:2.3:a:cisco:firepower_management_center_virtual_appliance:6.6.1:*:*:*:*:*:*:*:
- cpe:2.3:a:cisco:firepower_management_center_virtual_appliance:6.7.0:*:*:*:*:*:*:*:
- cpe:2.3:a:cisco:firepower_management_center_virtual_appliance:7.0.0:*:*:*:*:*:*:*:
- cpe:2.3:a:cisco:firepower_management_center_virtual_appliance:7.1.0:*:*:*:*:*:*:*:
- cpe:2.3:a:cisco:firepower_threat_defense:*:*:*:*:*:*:*:*:
- cpe:2.3:a:cisco:sourcefire_defense_center:6.1.0:*:*:*:*:*:*:*:
- cpe:2.3:a:cisco:sourcefire_defense_center:6.2.0:*:*:*:*:*:*:*:
- cpe:2.3:a:cisco:sourcefire_defense_center:6.2.3:*:*:*:*:*:*:*:
- cpe:2.3:a:cisco:sourcefire_defense_center:6.3.0:*:*:*:*:*:*:*:
- cpe:2.3:a:cisco:sourcefire_defense_center:6.4.0:*:*:*:*:*:*:*:
- cpe:2.3:a:cisco:sourcefire_defense_center:6.4.0.11:*:*:*:*:*:*:*:
- cpe:2.3:a:cisco:sourcefire_defense_center:6.5.0:*:*:*:*:*:*:*:
- cpe:2.3:a:cisco:sourcefire_defense_center:6.6.0:*:*:*:*:*:*:*:
- cpe:2.3:a:cisco:sourcefire_defense_center:6.6.1:*:*:*:*:*:*:*:
- cpe:2.3:a:cisco:sourcefire_defense_center:6.7.0:*:*:*:*:*:*:*:
- cpe:2.3:a:cisco:sourcefire_defense_center:7.0.0:*:*:*:*:*:*:*:
- cpe:2.3:a:cisco:sourcefire_defense_center:7.1.0:*:*:*:*:*:*:*:
No vendor comments have been submitted for this CVE
Social Mentions
Source | Title | Posted (UTC) |
---|---|---|
![]() |
CVE-2021-34755 : Multiple vulnerabilities in the CLI of Cisco Firepower Threat Defense FTD Software could allow a… twitter.com/i/web/status/1… | 2021-10-27 19:06:20 |