QID 316972

Date Published: 2021-06-01

QID 316972: Cisco Adaptive Security Appliance Software for Firepower 1000 and 2100 Series Appliances Command Injection Vulnerability(cisco-sa-asa-cmdinj-TKyQfDcU)

A vulnerability in the upgrade process of Cisco Adaptive Security Appliance (ASA) Software
could allow an authenticated, local attacker to inject
commands that could be executed with root privileges on the underlying operating system (OS).

Affected Products
Cisco devices if they were running a vulnerable release of Cisco ASA Software :
Firepower 1000 Series
Firepower 2100 Series

ASA Vulnerable Versions:
From 9.13 Prior to 9.13.1.21
From 9.14 Prior to 9.14.2.13
From 9.15 Prior to 9.15.1.10
Note: Firepower Threat Defense Software for Firepower 1000 and 2100 Series Appliances not supported.

QID Detection Logic (Authenticated):
The check matches Cisco ASA OS version retrieved via Unix Auth using "version" command.

A successful exploit could allow the attacker to inject commands that could be executed with root privileges on the underlying OS.

  • CVSS V3 rated as High - 6.7 severity.
  • CVSS V2 rated as High - 7.2 severity.
  • Solution

    Customers are advised to refer to cisco-sa-asa-cmdinj-TKyQfDcU for more information.

    CVEs related to QID 316972

    Software Advisories
    Advisory ID Software Component Link
    cisco-sa-asa-cmdinj-TKyQfDcU URL Logo tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-asa-cmdinj-TKyQfDcU