CVE Database
/

CVE-2024-20370

Back to search

CVE-2024-20370

Published: Oct 23, 2024

Modified: Oct 26, 2024

PUBLISHED

CVSS v3.1

6.0

MEDIUM

Description

A vulnerability in the Cisco FXOS CLI feature on specific hardware platforms for Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an authenticated, local attacker to elevate their administrative privileges to root. The attacker would need valid administrative credentials on the device to exploit this vulnerability. This vulnerability exists because certain system configurations and executable files have insecure storage and permissions. An attacker could exploit this vulnerability by authenticating on the device and then performing a series of steps that includes downloading malicious system files and accessing the Cisco FXOS CLI to configure the attack. A successful exploit could allow the attacker to obtain root access on the device.

VendorProductVersions

Cisco

Cisco Adaptive Security Appliance (ASA) Software

affected
9.17.1
affected
9.17.1.7
affected
9.17.1.9
affected
9.17.1.10
affected
9.17.1.11

+35 more versions

Cisco

Cisco Firepower Threat Defense Software

affected
7.1.0
affected
7.1.0.1
affected
7.1.0.2
affected
7.1.0.3
affected
7.2.0

+20 more versions

Weaknesses (CWE)

CVSS v3.1 Details

CVSS v3.1 Vector

CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N

Attack Vector

Local

Attack Complexity

Low

Privileges Required

High

User Interaction

None

Scope

Unchanged

Confidentiality

High

Integrity

High

Availability

None

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now