Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
Cisco FXOS Software Command Injection Vulnerability
Vulnerability Description
A vulnerability in the CLI of Cisco FXOS Software could allow an authenticated, local attacker to inject arbitrary commands that are executed with root privileges. The attacker would need to have Administrator privileges on the device. This vulnerability is due to insufficient input validation of commands supplied by the user. An attacker could exploit this vulnerability by authenticating to a device and submitting crafted input to the affected command. A successful exploit could allow the attacker to execute commands on the underlying operating system with root privileges.
CVSS Information
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Vulnerability Type
OS命令中使用的特殊元素转义处理不恰当(OS命令注入)
Vulnerability Title
Cisco FXOS Software 操作系统命令注入漏洞
Vulnerability Description
Cisco FXOS Software是美国思科(Cisco)公司的一套运行在思科安全设备中的防火墙软件。 Cisco FXOS存在操作系统命令注入漏洞,该漏洞源于dui用户提供的命令输入验证不足。攻击者利用该漏洞执行任意代码。以下产品及版本受到影响:Firepower 4100 Series、Firepower 9300 Security Appliances。
CVSS Information
N/A
Vulnerability Type
N/A