Input validation error in Cisco Secure Firewall Management Center (formerly Firepower Management Center, FMC) - CVE-2019-12689

 

Input validation error in Cisco Secure Firewall Management Center (formerly Firepower Management Center, FMC) - CVE-2019-12689

Published: October 8, 2019


Vulnerability identifier: #VU21625
CSH Severity: Medium
CVSS v4: 7.7 [CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2019-12689
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to execute arbitrary code on the target system.

The vulnerability exists due to insufficient validation of user-supplied input in the web-based management interface. A remote authenticated attacker can send malicious commands to the web-based management interface and execute arbitrary code on the underlying operating system of the affected device.


Affected software

Cisco Secure Firewall Management Center (formerly Firepower Management Center, FMC)

How to mitigate CVE-2019-12689

Install updates from vendor's website.

Cisco Secure Firewall Management Center (formerly Firepower Management Center, FMC) - addressed in versions 6.2.2.2, 6.2.3

External References

Related Security Bulletins