← All CVEs

CVE-2017-12243

high · 7.8

A vulnerability in the Cisco Unified Computing System (UCS) Manager, Cisco Firepower 4100 Series Next-Generation Firewall (NGFW), and Cisco Firepower 9300 Security Appliance could allow an authenticated, local attacker to obtain root shell privileges on the device, aka Command Injection. The vulnerability is due to improper validation of string input in the shell application. An attacker could exploit this vulnerability through the use of malicious commands. A successful exploit could allow the attacker to obtain root shell privileges on the device. Cisco Bug IDs: CSCvf20741, CSCvf60078.

7.8
CVSS
77.1%
EPSS (exploit prob.)
100th
EPSS percentile
2017-11-02
Published

CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Weaknesses

CWE-78

Affected products

VendorProductAffected versions
ciscounified_computing_system_manager_firmwareall versions
ciscounified_computing_system_managerall versions
ciscofirepower_9300_security_appliance_firmwareall versions
ciscofirepower_9300_security_applianceall versions
ciscofirepower_4100_next-generation_firewall_firmwareall versions
ciscofirepower_4110_next-generation_firewallall versions
ciscofirepower_4120_next-generation_firewallall versions
ciscofirepower_4140_next-generation_firewallall versions
ciscofirepower_4150_next-generation_firewallall versions

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2017-12243