CVE-2020-3167High· 7.8▾ TwilightA vulnerability in the CLI of Cisco FXOS Software and Cisco UCS Manager Software could allow an authenticated, local attacker to execute arbitrary commands on the underlying operating system (OS). The vulnerability is due to insufficient…
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 42.9 · likelihood 0.2 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Aug 11.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
0.5%
0.5% → 0.9%
A vulnerability in the CLI of Cisco FXOS Software and Cisco UCS Manager Software could allow an authenticated, local attacker to execute arbitrary commands on the underlying operating system (OS). The vulnerability is due to insufficient input validation. An attacker could exploit this vulnerability by including crafted arguments to specific commands. A successful exploit could allow the attacker to execute arbitrary commands on the underlying OS with the privileges of the currently logged-in user for all affected platforms excluding Cisco UCS 6400 Series Fabric Interconnects. On Cisco UCS 6400 Series Fabric Interconnects, the injected commands are executed with root privileges.
secure_firewall_threat_defense >= 6.2.2, < 6.2.3.13secure_firewall_threat_defense >= 6.3.0, < 6.4.0.8secure_firewall_threat_defense >= 6.5.0, < 6.5.0.2adaptive_security_appliance_software >= 9.8, < 9.9.2.66adaptive_security_appliance_software >= 9.10, < 9.12.3.6adaptive_security_appliance_software >= 9.13, < 9.13.1.5firepower_extensible_operating_system < 2.4.1.234ucs_manager < 3.2\(3n\)ucs_manager >= 4.0, < 4.0\(4g\)Upgrade past the affected range:
secure_firewall_threat_defense 6.5.0.2adaptive_security_appliance_software 9.13.1.5firepower_extensible_operating_system 2.4.1.234ucs_manager 4.0\(4g\)Connected by shared product, vendor, weakness, or advisory.
CVE-2021-1448High· 7.8A vulnerability in the CLI of Cisco Firepower Threat Defense (FTD) Software could allow an authenticated, local attacker to execute arbitrary commands with root privileges on the underlying operating system of an affected device that is …
CVE-2019-12699High· 7.8Multiple vulnerabilities in the CLI of Cisco FXOS Software and Cisco Firepower Threat Defense (FTD) Software could allow an authenticated, local attacker to execute commands on the underlying operating system (OS) with root privileges
CVE-2019-1709Medium· 6.0A vulnerability in the CLI of Cisco Firepower Threat Defense (FTD) Software could allow an authenticated, local attacker to perform a command injection attack
CVE-2018-0453High· 8.2A vulnerability in the Sourcefire tunnel control channel protocol in Cisco Firepower System Software running on Cisco Firepower Threat Defense (FTD) sensors could allow an authenticated, local attacker to execute specific CLI commands wi…
CVE-2017-3806Medium· 5.3A vulnerability in CLI command processing in the Cisco Firepower 4100 Series Next-Generation Firewall and Cisco Firepower 9300 Security Appliance could allow an authenticated, local attacker to inject arbitrary shell commands that are ex…
CVE-2025-20224Medium· 5.8A vulnerability in the Internet Key Exchange Version 2 (IKEv2) module of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Secure Firewall Threat Defense (FTD) Software could allow an unauthenticated, remote attacker t…