CyberzSOC

Publication detail
← Back to advisories & guidance

2024-114: Multiple Critical CISCO Vulnerabilities ↗ source

October 25, 2024 CERT-EU Advisory
Co-sealed by: CERT-EU, USDA

Summary

These vulnerabilities can potentially allow attackers to conduct various types of attacks, including command injection, remote command execution, arbitrary command execution, and unauthorised access through static credentials due to improper input validation or insecure handling of web services components. Successful exploitation could allow attackers to execute arbitrary commands, gain root-level access through SSH, or gain unauthorised access via static credentials. Command Injection Vulnerability: A vulnerability in the web-based management interface of Cisco Secure Firewall Management Center (FMC) Software could allow an authenticated, remote attacker to execute arbitrary commands on the underlying operating system as root or to execute commands on managed Cisco Firepower Threat Defense (FTD) devices. This vulnerability is due to insufficient input validation of certain HTTP requests. To exploit this vulnerability, the attacker would need valid credentials for a user account with at least the role of Security Analyst (Read Only) [2]. 2.

News Coverage

No coverage found in monitored research blogs or news feeds.

CVEs Referenced in This Publication

No CVEs are referenced in this publication.

Vendors Named in This Publication

Each vendor links to its Known Exploited Vulnerabilities catalog page. Only vendors that appear in the KEV catalog are listed, either because the publication cites one of their KEV entries or because it names them directly.