CVE-2023-20063
CVSS 3.1 Score 8.2 of 10 (high)
Details
Summary
CVE-2023-20063 is a newly disclosed vulnerability that affects the inter-device communication mechanisms between Cisco Firepower Threat Defense (FTD) Software and Firepower Management (FMC) Software. This issue stems from insufficient validation of user-supplied input and could allow an authenticated, local attacker to execute arbitrary commands with root permissions on the underlying operating system of an affected device. An attacker could potentially exploit this vulnerability by accessing the expert mode of an affected device and submitting malicious commands to a connected system. Successful exploitation could result in the execution of arbitrary code on an FMC device if the attacker has administrative privileges on an associated FTD device. Conversely, an attacker with administrative privileges on an associated FMC device could exploit this vulnerability to execute arbitrary code on an FTD device.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- Cisco Firepower Threat Defense
- Cisco FirePOWER Management Center
Affected Vendors
- Cisco Systems Inc