Use of Hard-coded Password in Cisco Systems, Inc products - CVE-2024-20412

 

Use of Hard-coded Password in Cisco Systems, Inc products - CVE-2024-20412

Published: October 25, 2024


Vulnerability identifier: #VU99342
CSH Severity: Low
CVSS v4: 8.6 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2024-20412
CWE-ID: CWE-259
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local attacker to compromise the target system.

The vulnerability exists due to the presence of static accounts with hard-coded passwords on an affected system. A local attacker can access the target system and retrieve sensitive information, perform limited troubleshooting actions, modify some configuration options or render the device unable to boot to the operating system.


Affected software

Firepower 4200 Series Appliances
Firepower 3100 Series Appliances
Firepower 1000 Series Appliances
Firepower 2100 Series Security Appliances
Cisco Firewall Threat Defense (FTD)

How to mitigate CVE-2024-20412

Install updates from vendor's website.

Cisco Firewall Threat Defense (FTD) - addressed in versions 7.2.8, 7.2.8.1, 7.2.9, 7.4.2, 7.4.2.1, 7.6.0

External References

Related Security Bulletins