Remote Command Injection Vulnerability in Cisco Firepower Devices
CVE-2017-12277
Key Information:
- Vendor
- Cisco
- Vendor
- CVE Published:
- 2 November 2017
Summary
A significant vulnerability has been identified in the Smart Licensing Manager service of Cisco's Firepower 4100 Series Next-Generation Firewall and Firepower 9300 Security Appliance. This issue stems from inadequate input validation on certain Smart Licensing configuration parameters, allowing an authenticated remote attacker to inject and execute arbitrary commands with root privileges. By configuring a malicious URL within the affected service, an attacker may exploit this vulnerability. This incomplete validation creates a high risk for systems running specific FX-OS code versions. Mitigation strategies should be employed promptly to address this vulnerability and secure affected devices.
Affected Version(s)
Cisco Firepower 4100 Series NGFW and Firepower 9300 Security Appliance Cisco Firepower 4100 Series NGFW and Firepower 9300 Security Appliance
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved