CVE-2019-12687
Cisco Firepower Management Center Remote Code Execution Vulnerability
Vexday Risk Score
21Low
SSVC decision (CISA)
Track
No exploitation signal → monitor
CVSS 8.8EPSS 3.4%KEV nãoPoC —Nuclei —Metasploit —Patch referenciado
Lifecycle
02 Oct 2019Published on NVD
Recommendation: Monitor — no exploitation signal at the moment.
A vulnerability in the web UI of the Cisco Firepower Management Center (FMC) could allow an authenticated, remote attacker to execute arbitrary commands on an affected device. The vulnerability is due to insufficient input validation. An attacker could exploit this vulnerability by sending crafted input to the web UI. A successful exploit could allow the attacker to execute arbitrary commands within the affected device.
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Affected products
Cisco · Cisco Firepower Management CenterWant to know if your infrastructure is exposed to this?
Talk to TrueHacking →