CVE-2022-20934

MEDIUM

Cisco Firepower Threat Defense and FXOS - Authenticated OS Command Injection via CLI

Title source: llm
STIX 2.1

Description

A vulnerability in the CLI of Cisco Firepower Threat Defense (FTD) Software and Cisco FXOS Software could allow an authenticated, local attacker to execute arbitrary commands on the underlying operating system as root. This vulnerability is due to improper input validation for specific CLI commands. An attacker could exploit this vulnerability by injecting operating system commands into a legitimate command. A successful exploit could allow the attacker to escape the restricted command prompt and execute arbitrary commands on the underlying operating system. To successfully exploit this vulnerability, an attacker would need valid Administrator credentials.

Scores

CVSS v3 6.0
EPSS 0.0011
EPSS Percentile 29.0%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-78 CWE-77
Status published
Products (50)
cisco/firepower_extensible_operating_system 1.1.1.147
cisco/firepower_extensible_operating_system 1.1.1.160
cisco/firepower_extensible_operating_system 1.1.2.51
cisco/firepower_extensible_operating_system 1.1.2.178
cisco/firepower_extensible_operating_system 1.1.3.84
cisco/firepower_extensible_operating_system 1.1.3.86
cisco/firepower_extensible_operating_system 1.1.3.97
cisco/firepower_extensible_operating_system 1.1.4.95
cisco/firepower_extensible_operating_system 1.1.4.117
cisco/firepower_extensible_operating_system 1.1.4.140
... and 40 more
Published Nov 15, 2022
Tracked Since Feb 18, 2026