PT-2020-5099 · Cisco · Cisco Firepower Management Center+1
Published
2020-10-21
·
Updated
2024-11-26
·
CVE-2020-3550
CVSS v2.0
8.5
High
| Vector | AV:N/AC:L/Au:S/C:C/I:C/A:N |
Name of the Vulnerable Software and Affected Versions
Cisco Firepower Management Center (FMC) Software (affected versions not specified)
Cisco Firepower Threat Defense (FTD) Software (affected versions not specified)
Description
A vulnerability in the sfmgr daemon could allow an authenticated, remote attacker to perform directory traversal and access directories outside the restricted path due to insufficient input validation. An attacker could exploit this vulnerability by using a relative path in specific sfmgr commands, potentially allowing them to read or write arbitrary files on an sftunnel-connected peer device.
Recommendations
For Cisco Firepower Management Center (FMC) Software, update to a version that addresses the directory traversal issue in the sfmgr daemon.
For Cisco Firepower Threat Defense (FTD) Software, update to a version that addresses the directory traversal issue in the sfmgr daemon.
As a temporary workaround, consider restricting access to the sfmgr daemon and limiting the use of relative paths in sfmgr commands until a patch is available.
Fix
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Cisco Firepower Management Center
Cisco Ftd