PT-2021-4921 · Cisco · Cisco Ftd

Brandon Sakai

·

Published

2021-10-27

·

Updated

2022-10-27

·

CVE-2021-34761

CVSS v2.0

6.6

Medium

VectorAV:L/AC:L/Au:N/C:N/I:C/A:C
Name of the Vulnerable Software and Affected Versions Cisco Firepower Threat Defense (FTD) Software (affected versions not specified)
Description A vulnerability in Cisco Firepower Threat Defense (FTD) Software could allow an authenticated, local attacker to overwrite or append arbitrary data to system files using root-level privileges. The attacker must have administrative credentials on the device. This vulnerability is due to incomplete validation of user input for a specific CLI command. An attacker could exploit this vulnerability by authenticating to the device with administrative privileges and issuing a CLI command with crafted user parameters, such as username or password. A successful exploit could allow the attacker to overwrite or append arbitrary data to system files using root-level privileges.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

RCE

Exposure of Resource to Wrong Sphere

Weakness Enumeration

Related Identifiers

BDU:2021-05659
CVE-2021-34761

Affected Products

Cisco Ftd