CVE-2023-20063

CVSS 3.1 Score 8.2 of 10 (high)

Details

Published Nov 1, 2023
Updated: Jan 25, 2024
CWE ID 94
CWE ID 20

Summary

CVE-2023-20063 is a newly disclosed vulnerability that affects the inter-device communication mechanisms between Cisco Firepower Threat Defense (FTD) Software and Firepower Management (FMC) Software. This issue stems from insufficient validation of user-supplied input and could allow an authenticated, local attacker to execute arbitrary commands with root permissions on the underlying operating system of an affected device. An attacker could potentially exploit this vulnerability by accessing the expert mode of an affected device and submitting malicious commands to a connected system. Successful exploitation could result in the execution of arbitrary code on an FMC device if the attacker has administrative privileges on an associated FTD device. Conversely, an attacker with administrative privileges on an associated FMC device could exploit this vulnerability to execute arbitrary code on an FTD device.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share

Affected Products

  • Cisco Firepower Threat Defense
  • Cisco FirePOWER Management Center

Affected Vendors

  • Cisco Systems Inc