vulnerability in the CLI of Cisco FXOS Software could allow an authenticated, local attacker to execute arbitrary commands on the underlying Linux operating system with a privilege level of root on an affected device. The vulnerability is due to insufficient validation of arguments passed to a specific CLI command on the affected device. An attacker could exploit this vulnerability by including malicious input as the argument of an affected command. A successful exploit could allow the attacker to execute arbitrary commands on the underlying Linux operating system with root privileges. An attacker would need valid administrator credentials to exploit this vulnerability.
| Link | Resource |
|---|---|
| https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20200226-fpwr-cmdinj | Patch Vendor Advisory |
| https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20200226-fpwr-cmdinj | Patch Vendor Advisory |
Configuration 1 (hide)
| AND |
|
21 Nov 2024, 05:30
| Type | Values Removed | Values Added |
|---|---|---|
| References | () https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20200226-fpwr-cmdinj - Patch, Vendor Advisory |
Published : 2020-02-26 17:15
Updated : 2024-11-21 05:30
NVD link : CVE-2020-3169
Mitre link : CVE-2020-3169
CVE.ORG link : CVE-2020-3169
JSON object : View
- firepower_9300_sm-48
- firepower_9300_sm-44_x_3
- firepower_9300_sm-56
- firepower_9300_sm-40
- firepower_4120
- firepower_extensible_operating_system
- firepower_4115
- firepower_9300_sm-44
- firepower_4125
- firepower_9300_sm-36
- firepower_4145
- firepower_9300_sm-56_x_3
- firepower_4150
- firepower_4110
- firepower_9300_sm-24
- firepower_4140
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')