Permissions, Privileges, and Access Controls in Cisco Systems, Inc products - CVE-2020-3514
Published: October 21, 2020 / Updated: October 27, 2020
Vulnerability details
The vulnerability allows a local user to escalate privileges on the system.
The vulnerability exists due to a configuration file that is used at container startup has insufficient protections in the multi-instance feature. A local administrator can modify a specific container configuration file on the underlying file system and execute commands with root privileges within the host namespace.
Affected software
Firepower 9300 Series Security Appliances
Cisco Firewall Threat Defense (FTD)