SB2017110213 - Command execution in Cisco Firepower 4100 Series NGFW and Firepower 9300 Security Appliance
Published: November 2, 2017
Security Bulletin ID
SB2017110213
Severity
Low
Patch available
YES
Number of vulnerabilities
1
Exploitation vector
Remote access
Highest impact
Code execution
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Command injection (CVE-ID: CVE-2017-12277)
The vulnerability allows a remote authenticated attacker to execute arbitrary commands on the target system.The weakness exists in the Smart Licensing Manager service of the Cisco Firepower 4100 Series Next-Generation Firewall (NGFW) and Firepower 9300 Security Appliance due to insufficient input validation of certain Smart Licensing configuration parameters. A remote attacker can configure a malicious URLand execute arbitrary commands with root privileges.
Remediation
Install update from vendor's website.