Command Injection Vulnerability in Cisco Firepower Appliances
CVE-2017-3806
5.3MEDIUM
Key Information:
- Vendor
- Cisco
- Vendor
- CVE Published:
- 3 February 2017
Summary
A command injection vulnerability exists in the CLI command processing of Cisco Firepower 4100 Series and Firepower 9300 Security Appliance. This flaw can allow an authenticated, local attacker to execute arbitrary shell commands on the device, potentially compromising its security. It is crucial for users to update to the fixed releases to mitigate this risk and maintain the integrity of their network systems. For more information, refer to the Cisco Security Advisory.
Affected Version(s)
Cisco Firepower 4100 Series Next-Generation Firewall and Cisco Firepower 9300 Security Appliance 2.0(1.68) Cisco Firepower 4100 Series Next-Generation Firewall and Cisco Firepower 9300 Security Appliance 2.0(1.68)
References
CVSS V3.1
Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved