CVE-2024-20412

A vulnerability in Cisco Firepower Threat Defense (FTD) Software for Cisco Firepower 1000, 2100, 3100, and 4200 Series could allow an unauthenticated, local attacker to access an affected system using

Severity
Critical 9.3
CVSS 3.1
Adjacent, local or physical access what this means
Exploited
Not listed
EPSS
0.002
10.7th percentile
Discovered by
Vendor
Vendor-published field
Published
Oct 23, 2024
Assigned by cisco

Description

A vulnerability in Cisco Firepower Threat Defense (FTD) Software for Cisco Firepower 1000, 2100, 3100, and 4200 Series could allow an unauthenticated, local attacker to access an affected system using static credentials. This vulnerability is due to the presence of static accounts with hard-coded passwords on an affected system. An attacker could exploit this vulnerability by logging in to the CLI of an affected device with these credentials. A successful exploit could allow the attacker to access the affected system and retrieve sensitive information, perform limited troubleshooting actions, modify some configuration options, or render the device unable to boot to the operating system, requiring a reimage of the device.

Weakness: CWE-259

Affected products

Vendor Product Category Matched by
Cisco Cisco Firepower Threat Defense (FTD) Check your version Firewall / NGFW cna-assigner
Vendor-reported products (2)
  • Cisco · Cisco Firepower Threat Defense Software
  • cisco · firepower_threat_defense_software

Vendor advisory

cisco-sa-ftd-statcred-dFC8tXT5

Cisco Firepower Threat Defense Software for Firepower 1000, 2100, 3100, and 4200 Series Static Credential Vulnerability

Cisco’s rating: Critical (advisory CVSS 9.3) · Published Oct 23, 2024

Bug ID: CSCwk07982

The vendor’s rating applies to the whole advisory and can differ from this CVE’s own CVSS severity. Where this comes from

Something wrong here?