OS Command Injection in Firepower 4100 Series Security Appliances and Cisco Firepower 9300 Security Appliance - CVE-2022-20865
Published: August 24, 2022
Vulnerability identifier: #VU66752
CSH Severity: Low
CVSS v4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2022-20865
CWE-ID: CWE-78
Exploitation vector: Local access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a local user to escalate privileges on the system.
The vulnerability exists due to improper input validation in the CLI. A local user can pass specially crafted arguments to a CLI command and execute arbitrary OS commands with root privileges.
Affected software
Firepower 4100 Series Security Appliances
Cisco Firepower 9300 Security Appliance
Cisco Firepower 9300 Security Appliance
How to mitigate CVE-2022-20865
Install updates from vendor's website.