CVE Vulnerabilities

CVE-2020-3352

Hidden Functionality

Published: Oct 21, 2020 | Modified: Nov 21, 2024
CVSS 3.x
5.5
MEDIUM
Source:
NVD
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
CVSS 2.x
1.9 LOW
AV:L/AC:M/Au:N/C:N/I:P/A:N
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

A vulnerability in the CLI of Cisco Firepower Threat Defense (FTD) Software could allow an authenticated, local attacker to access hidden commands. The vulnerability is due to the presence of undocumented configuration commands. An attacker could exploit this vulnerability by performing specific steps that make the hidden commands accessible. A successful exploit could allow the attacker to make configuration changes to various sections of an affected device that should not be exposed to CLI access.

Weakness

The product contains functionality that is not documented, not part of the specification, and not accessible through an interface or command sequence that is obvious to the product’s users or administrators.

Affected Software

NameVendorStart VersionEnd Version
Firepower_threat_defenseCisco*6.3.0.6 (excluding)
Firepower_threat_defenseCisco6.4.0 (including)6.4.0.10 (excluding)
Firepower_threat_defenseCisco6.5.0 (including)6.5.0.5 (excluding)
Firepower_threat_defenseCisco6.6.0 (including)6.6.1 (excluding)

Potential Mitigations

References