PT-2020-5099 · Cisco · Cisco Firepower Management Center+1

Published

2020-10-21

·

Updated

2024-11-26

·

CVE-2020-3550

CVSS v2.0

8.5

High

VectorAV:N/AC:L/Au:S/C:C/I:C/A:N
Name of the Vulnerable Software and Affected Versions Cisco Firepower Management Center (FMC) Software (affected versions not specified) Cisco Firepower Threat Defense (FTD) Software (affected versions not specified)
Description A vulnerability in the sfmgr daemon could allow an authenticated, remote attacker to perform directory traversal and access directories outside the restricted path due to insufficient input validation. An attacker could exploit this vulnerability by using a relative path in specific sfmgr commands, potentially allowing them to read or write arbitrary files on an sftunnel-connected peer device.
Recommendations For Cisco Firepower Management Center (FMC) Software, update to a version that addresses the directory traversal issue in the sfmgr daemon. For Cisco Firepower Threat Defense (FTD) Software, update to a version that addresses the directory traversal issue in the sfmgr daemon. As a temporary workaround, consider restricting access to the sfmgr daemon and limiting the use of relative paths in sfmgr commands until a patch is available.

Fix

Path traversal

Weakness Enumeration

Related Identifiers

BDU:2020-05692
CVE-2020-3550

Affected Products

Cisco Firepower Management Center
Cisco Ftd