---
id: CVE-2019-1709
title: >-
  A vulnerability in the CLI of Cisco Firepower Threat Defense (FTD) Software
  could allow an authenticated, local attacker to perform a command injection
  attack
summary: >-
  A vulnerability in the CLI of Cisco Firepower Threat Defense (FTD) Software
  could allow an authenticated, local attacker to perform a command injection
  attack. The vulnerability is due to insufficient input validation. An attacker
  could …
severity: medium
cvss: 6
cvssVector: 'CVSS:3.0/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:H'
cwe:
  - CWE-78
  - CWE-78
vendor: cisco
product: secure_firewall_management_center
affected:
  - secure_firewall_management_center = 6.3.0
  - secure_firewall_threat_defense = 6.0.0
  - secure_firewall_threat_defense = 6.0.1
  - secure_firewall_threat_defense = 6.1.0
  - secure_firewall_threat_defense = 6.2.0
  - secure_firewall_threat_defense = 6.2.1
  - secure_firewall_threat_defense = 6.2.2
  - secure_firewall_threat_defense = 6.2.3
published: '2019-05-03'
updated: '2026-08-11'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2019-1709'
references:
  - url: 'http://www.securityfocus.com/bid/108156'
    label: psirt@cisco.com
  - url: >-
      https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20190501-frpwr-cmd-inj
    label: psirt@cisco.com
  - url: 'http://www.securityfocus.com/bid/108156'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20190501-frpwr-cmd-inj
    label: af854a3a-2127-422b-91ae-364da2661108
tags:
  - nvd
epss: 0.00676
epssPercentile: 0.50801
ingestedAt: '2026-08-11T19:48:26.647Z'
---

## Overview

A vulnerability in the CLI of Cisco Firepower Threat Defense (FTD) Software could allow an authenticated, local attacker to perform a command injection attack. The vulnerability is due to insufficient input validation. An attacker could exploit this vulnerability by injecting commands into arguments for a specific command. A successful exploit could allow the attacker to execute commands with root privileges.

## Affected

- `secure_firewall_management_center = 6.3.0`
- `secure_firewall_threat_defense = 6.0.0`
- `secure_firewall_threat_defense = 6.0.1`
- `secure_firewall_threat_defense = 6.1.0`
- `secure_firewall_threat_defense = 6.2.0`
- `secure_firewall_threat_defense = 6.2.1`
- `secure_firewall_threat_defense = 6.2.2`
- `secure_firewall_threat_defense = 6.2.3`

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
