Learn about CVE-2019-12699, multiple vulnerabilities in Cisco FXOS Software and Firepower Threat Defense Software allowing local attackers to execute commands with root privileges. Find mitigation steps and patching details here.
Cisco FXOS Software and Firepower Threat Defense Software Command Injection Vulnerabilities were identified, potentially allowing a local attacker to execute commands with root privileges.
Understanding CVE-2019-12699
Multiple vulnerabilities in the CLI of Cisco FXOS Software and Cisco Firepower Threat Defense (FTD) Software could enable an authenticated attacker to execute commands on the underlying OS with root privileges.
What is CVE-2019-12699?
The vulnerabilities stem from inadequate input validation in the CLI of Cisco FXOS Software and Cisco FTD Software, allowing a local attacker to manipulate CLI command arguments to execute commands with root privileges on the OS.
The Impact of CVE-2019-12699
The vulnerabilities have a CVSS base score of 8.8, indicating a high severity level. The impact includes high confidentiality, integrity, and availability impacts, with low attack complexity and privileges required.
Technical Details of CVE-2019-12699
The technical details of the vulnerabilities are as follows:
Vulnerability Description
Affected Systems and Versions
Exploitation Mechanism
Mitigation and Prevention
To address CVE-2019-12699, consider the following steps:
Immediate Steps to Take
Long-Term Security Practices
Patching and Updates