QID 317271
Date Published: 2022-11-15
QID 317271: Cisco Firepower Management Center (FMC) Software Command Injection Vulnerabilities (cisco-sa-fmc-cmd-inj-Z3B5MY35)
Multiple vulnerabilities in the web management interface of Cisco Firepower Management Center (FMC) Software could allow an authenticated, remote attacker to execute arbitrary commands on the underlying operating system.
Affected Products
This vulnerability affects Cisco products if they are running a vulnerable release of Cisco FMC Software.
6.7.0 prior to version 7.2.0
QID Detection Logic (Authenticated):
This QID will check the version retrieved via Unix Auth using "show version" command.
To successfully exploit these vulnerabilities, an attacker would need valid credentials for a user who has Devices permissions.
Solution
Customers are advised to refer to cisco-sa-fmc-cmd-inj-Z3B5MY35 for more information.
Vendor References
- cisco-sa-fmc-cmd-inj-Z3B5MY35 -
tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-fmc-cmd-inj-Z3B5MY35
CVEs related to QID 317271
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| cisco-sa-fmc-cmd-inj-Z3B5MY35 |
|