#VU27580 Input validation error in Cisco Firepower Device Manager On-Box


Published: 2020-05-07

Vulnerability identifier: #VU27580

Vulnerability risk: Low

CVSSv3.1: 5.7 [CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:H/E:U/RL:O/RC:C]

CVE-ID: CVE-2020-3309

CWE-ID: CWE-20

Exploitation vector: Network

Exploit availability: No

Vulnerable software:
Cisco Firepower Device Manager On-Box
Client/Desktop applications / Other client software

Vendor: Cisco Systems, Inc

Description

The vulnerability allows a remote user to overwrite arbitrary files on the target system.

The vulnerability exists due to insufficient validation of user-supplied input. A remote administrator can uploading a malicious file and overwrite arbitrary files on as well as modify the underlying operating system of an affected device.

Mitigation
Install updates from vendor's website.

Vulnerable software versions

Cisco Firepower Device Manager On-Box: All versions


External links
http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-fdmfo-HvPWKxDe


Q & A

Can this vulnerability be exploited remotely?

Yes. This vulnerability can be exploited by a remote authenticated privileged user via the Internet.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.


Latest bulletins with this vulnerability