CVE-2017-6601

HIGH

Cisco UCS Manager, Firepower 4100/9300 - Authenticated OS Command Injection via CLI

Title source: llm
STIX 2.1

Description

A vulnerability in the CLI of the Cisco Unified Computing System (UCS) Manager, Cisco Firepower 4100 Series Next-Generation Firewall (NGFW), and Cisco Firepower 9300 Security Appliance could allow an authenticated, local attacker to perform a command injection attack. More Information: CSCvb61384 CSCvb86764. Known Affected Releases: 2.0(1.68) 3.1(1k)A. Known Fixed Releases: 92.2(1.101) 92.1(1.1647).

References (3)

Core 3
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_sectrack
http://www.securitytracker.com/id/1038196
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/97477

Scores

CVSS v3 7.1
EPSS 0.0082
EPSS Percentile 52.7%
Attack Vector LOCAL
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N

Details

CWE
CWE-78
Status published
Products (3)
cisco/firepower_extensible_operating_system 2.0\(1.68\)
cisco/unified_computing_system 3.1\(1k\)a
n/a/Cisco UCS Manager, Cisco Firepower 4100 Series NGFW, and Cisco Firepower 9300 Security Appliance Cisco UCS Manager, Cisco Firepower 4100 Series NGFW, and Cisco Firepower 9300 Security Appliance
Published Apr 07, 2017
Tracked Since Feb 18, 2026