CVE-2019-12675
moderate-risk
Published 2019-10-02
Multiple vulnerabilities in the multi-instance feature of Cisco Firepower Threat Defense (FTD) Software could allow an authenticated, local attacker to escape the container for their FTD instance and execute commands with root privileges in the host namespace. These vulnerabilities are due to insufficient protections on the underlying filesystem. An attacker could exploit these vulnerabilities by modifying critical files on the underlying filesystem. A successful exploit could allow the attacker to execute commands with root privileges within the host namespace. This could allow the attacker to impact other running FTD instances.
Do I need to act?
-
0.03% chance of exploitation
EPSS score — low exploit probability
-
Not on CISA KEV list
No confirmed active exploitation reported to CISA
?
Patch status unknown
Check vendor advisories for fix availability and mitigation guidance
8
CVSS 8.8/10
High
LOCAL
/ LOW complexity
Affected Products (9)
Firepower 9300 Firmware
Firepower 4115 Firmware
Firepower 4125 Firmware
Firepower 4145 Firmware
Firepower 4110 Firmware
Firepower 4120 Firmware
Firepower 4140 Firmware
Firepower 4150 Firmware
Affected Vendors
References (2)
42
/ 100
moderate-risk
Severity
27/34 · High
Exploitability
0/34 · Minimal
Exposure
15/34 · Moderate