---
id: CVE-2017-3806
title: >-
  A vulnerability in CLI command processing in the Cisco Firepower 4100 Series
  Next-Generation Firewall and Cisco Firepower 9300 Security Appliance could
  allow an authenticated, local attacker to inject arbitrary shell commands that
  are ex…
summary: >-
  A vulnerability in CLI command processing in the Cisco Firepower 4100 Series
  Next-Generation Firewall and Cisco Firepower 9300 Security Appliance could
  allow an authenticated, local attacker to inject arbitrary shell commands that
  are ex…
severity: medium
cvss: 5.3
cvssVector: 'CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L'
cwe:
  - CWE-78
vendor: cisco
product: secure_firewall_threat_defense
affected:
  - secure_firewall_threat_defense = 5.3.0
  - secure_firewall_threat_defense = 5.4.0
  - secure_firewall_threat_defense = 6.0.0
  - secure_firewall_threat_defense = 6.0.1
  - secure_firewall_threat_defense = 6.1.0
published: '2017-02-03'
updated: '2026-08-11'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2017-3806'
references:
  - url: 'http://www.securityfocus.com/bid/95943'
    label: psirt@cisco.com
  - url: >-
      https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20170201-fpw
    label: psirt@cisco.com
  - url: 'http://www.securityfocus.com/bid/95943'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20170201-fpw
    label: af854a3a-2127-422b-91ae-364da2661108
tags:
  - nvd
epss: 0.00345
epssPercentile: 0.28161
ingestedAt: '2026-08-11T19:48:25.178Z'
---

## Overview

A vulnerability in CLI command processing in the Cisco Firepower 4100 Series Next-Generation Firewall and Cisco Firepower 9300 Security Appliance could allow an authenticated, local attacker to inject arbitrary shell commands that are executed by the device. More Information: CSCvb61343. Known Affected Releases: 2.0(1.68). Known Fixed Releases: 2.0(1.118) 2.1(1.47) 92.1(1.1646) 92.1(1.1763) 92.2(1.101).

## Affected

- `secure_firewall_threat_defense = 5.3.0`
- `secure_firewall_threat_defense = 5.4.0`
- `secure_firewall_threat_defense = 6.0.0`
- `secure_firewall_threat_defense = 6.0.1`
- `secure_firewall_threat_defense = 6.1.0`

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
