PT-2017-3408 · Cisco · Cisco Firepower 9300 Security Appliance+2

Published

2017-11-01

·

Updated

2019-10-09

·

CVE-2017-12243

CVSS v2.0

7.2

High

VectorAV:L/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Cisco Unified Computing System (UCS) Manager (affected versions not specified) Cisco Firepower 4100 Series Next-Generation Firewall (NGFW) (affected versions not specified) Cisco Firepower 9300 Security Appliance (affected versions not specified)
Description The issue is related to improper validation of string input in the shell application, which could allow an authenticated, local attacker to obtain root shell privileges on the device. This can be exploited through the use of malicious commands, potentially giving the attacker root shell privileges.
Recommendations For Cisco Unified Computing System (UCS) Manager, consider restricting access to the shell application until a fix is available. For Cisco Firepower 4100 Series Next-Generation Firewall (NGFW), restrict the use of potentially malicious commands to minimize the risk of exploitation. For Cisco Firepower 9300 Security Appliance, as a temporary workaround, consider disabling the shell application until a patch is available. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Command Injection

OS Command Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2018-00196
CVE-2017-12243

Affected Products

Cisco Firepower 4100 Series Next-Generation Firewall
Cisco Firepower 9300 Security Appliance
Cisco Unified Computing System (Ucs) Manager