---
id: CVE-2020-3352
title: >-
  A vulnerability in the CLI of Cisco Firepower Threat Defense (FTD) Software
  could allow an authenticated, local attacker to access hidden commands
summary: >-
  A vulnerability in the CLI of Cisco Firepower Threat Defense (FTD) Software
  could allow an authenticated, local attacker to access hidden commands. The
  vulnerability is due to the presence of undocumented configuration commands.
  An attac…
severity: medium
cvss: 5.5
cvssVector: 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N'
cwe:
  - CWE-912
vendor: cisco
product: secure_firewall_threat_defense
affected:
  - secure_firewall_threat_defense < 6.3.0.6
  - 'secure_firewall_threat_defense >= 6.4.0, < 6.4.0.10'
  - 'secure_firewall_threat_defense >= 6.5.0, < 6.5.0.5'
  - 'secure_firewall_threat_defense >= 6.6.0, < 6.6.1'
patched:
  - secure_firewall_threat_defense 6.6.1
published: '2020-10-21'
updated: '2026-08-11'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2020-3352'
references:
  - url: >-
      https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ftd-hidcmd-pFDeWVBd
    label: psirt@cisco.com
  - url: >-
      https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ftd-hidcmd-pFDeWVBd
    label: af854a3a-2127-422b-91ae-364da2661108
tags:
  - nvd
epss: 0.00273
epssPercentile: 0.19947
ingestedAt: '2026-08-11T19:48:28.444Z'
---

## Overview

A vulnerability in the CLI of Cisco Firepower Threat Defense (FTD) Software could allow an authenticated, local attacker to access hidden commands. The vulnerability is due to the presence of undocumented configuration commands. An attacker could exploit this vulnerability by performing specific steps that make the hidden commands accessible. A successful exploit could allow the attacker to make configuration changes to various sections of an affected device that should not be exposed to CLI access.

## Affected

- `secure_firewall_threat_defense < 6.3.0.6`
- `secure_firewall_threat_defense >= 6.4.0, < 6.4.0.10`
- `secure_firewall_threat_defense >= 6.5.0, < 6.5.0.5`
- `secure_firewall_threat_defense >= 6.6.0, < 6.6.1`

## Remediation

Upgrade past the affected range:

- `secure_firewall_threat_defense 6.6.1`
