CVE-2019-12675CWE-116CWE-216

CVE-2019-12675

High · published October 2, 2019

CVSS v3.1
8.8
EPSS
1%
Percentile
52.0
In the wild
Unconfirmed
What it is

Multiple vulnerabilities in the multi-instance feature of Cisco Firepower Threat Defense (FTD) Software could allow an authenticated, local attacker to escape the container for their FTD instance and execute commands with root privileges in the host namespace. These vulnerabilities are due to insufficient protections on the underlying filesystem. An attacker could exploit these vulnerabilities by modifying critical files on the underlying filesystem. A successful exploit could allow the attacker to execute commands with root privileges within the host namespace. This could allow the attacker to impact other running FTD instances.

The record
Technical detail
CVSS v3.1
8.8 · HIGH
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
CVSS v4.0
Not supplied
EPSS
0.00734 · 52.0th percentile
Weaknesses
CWE-116 · Improper Encoding or Escaping of Output; CWE-216 · DEPRECATED: Containment Errors (Container Errors)
Published
2019-10-02T23:15Z
Affected products (9)
ProductVersionsFixed in
cisco/secure_firewall_threat_defense< 6.4.0.26.4.0.2
cisco/firepower_9300_firmwareall versions
cisco/firepower_4115_firmwareall versions
cisco/firepower_4125_firmwareall versions
cisco/firepower_4145_firmwareall versions
cisco/firepower_4110_firmwareall versions
cisco/firepower_4120_firmwareall versions
cisco/firepower_4140_firmwareall versions
cisco/firepower_4150_firmwareall versions
References (2)
EPSS history
Timeline
  • 02 OCT 19:06Z
    Cisco Firepower Threat Defense Software Multi-instance Container Escape Vulnerabilities
    cvelistv5