PT-2017-3408 · Cisco · Cisco Firepower 9300 Security Appliance+2

Publicado

2017-11-01

·

Atualizado

2019-10-09

·

CVE-2017-12243

CVSS v2.0

7.2

Alta

VetorAV:L/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Cisco Unified Computing System (UCS) Manager (affected versions not specified) Cisco Firepower 4100 Series Next-Generation Firewall (NGFW) (affected versions not specified) Cisco Firepower 9300 Security Appliance (affected versions not specified)
Description The issue is related to improper validation of string input in the shell application, which could allow an authenticated, local attacker to obtain root shell privileges on the device. This can be exploited through the use of malicious commands, potentially giving the attacker root shell privileges.
Recommendations For Cisco Unified Computing System (UCS) Manager, consider restricting access to the shell application until a fix is available. For Cisco Firepower 4100 Series Next-Generation Firewall (NGFW), restrict the use of potentially malicious commands to minimize the risk of exploitation. For Cisco Firepower 9300 Security Appliance, as a temporary workaround, consider disabling the shell application until a patch is available. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Command Injection

OS Command Injection

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2018-00196
CVE-2017-12243

Produtos afetados

Cisco Firepower 4100 Series Next-Generation Firewall
Cisco Firepower 9300 Security Appliance
Cisco Unified Computing System (Ucs) Manager