CVE-2019-12674 (CNNVD-201910-088)
中文标题:
Cisco Firepower 4100 Series Security Appliances和Firepower 9300 Series Security Appliances Cisco Firepower Threat Defense Software 安全漏洞
英文标题:
Cisco Firepower Threat Defense Software Multi-instance Container Escape Vulnerabilities
漏洞描述
中文描述:
Cisco Firepower 4100 Series Security Appliances和Firepower 9300 Series Security Appliances中的Cisco Firepower Threat Defense (FTD) Software的多实例功能存在安全漏洞,该漏洞源于程序没有对底层文件系统进行充分的保护。本地攻击者可通过修改底层文件系统上的重要文件利用该漏洞在主机名称空间中以root权限执行命令。
英文描述:
Multiple vulnerabilities in the multi-instance feature of Cisco Firepower Threat Defense (FTD) Software could allow an authenticated, local attacker to escape the container for their FTD instance and execute commands with root privileges in the host namespace. These vulnerabilities are due to insufficient protections on the underlying filesystem. An attacker could exploit these vulnerabilities by modifying critical files on the underlying filesystem. A successful exploit could allow the attacker to execute commands with root privileges within the host namespace. This could allow the attacker to impact other running FTD instances.
CWE类型:
标签:
受影响产品
| 厂商 | 产品 | 版本 | 版本范围 | 平台 | CPE |
|---|---|---|---|---|---|
| Cisco | Cisco Firepower Threat Defense Software | - | < n/a | - |
cpe:2.3:a:cisco:cisco_firepower_threat_defense_software:*:*:*:*:*:*:*:*
|
| cisco | firepower_threat_defense | * | - | - |
cpe:2.3:a:cisco:firepower_threat_defense:*:*:*:*:*:*:*:*
|
| cisco | firepower_9300_firmware | - | - | - |
cpe:2.3:o:cisco:firepower_9300_firmware:-:*:*:*:*:*:*:*
|
| cisco | firepower_4115_firmware | - | - | - |
cpe:2.3:o:cisco:firepower_4115_firmware:-:*:*:*:*:*:*:*
|
| cisco | firepower_4125_firmware | - | - | - |
cpe:2.3:o:cisco:firepower_4125_firmware:-:*:*:*:*:*:*:*
|
| cisco | firepower_4145_firmware | - | - | - |
cpe:2.3:o:cisco:firepower_4145_firmware:-:*:*:*:*:*:*:*
|
| cisco | firepower_4110_firmware | - | - | - |
cpe:2.3:o:cisco:firepower_4110_firmware:-:*:*:*:*:*:*:*
|
| cisco | firepower_4120_firmware | - | - | - |
cpe:2.3:o:cisco:firepower_4120_firmware:-:*:*:*:*:*:*:*
|
| cisco | firepower_4140_firmware | - | - | - |
cpe:2.3:o:cisco:firepower_4140_firmware:-:*:*:*:*:*:*:*
|
| cisco | firepower_4150_firmware | - | - | - |
cpe:2.3:o:cisco:firepower_4150_firmware:-:*:*:*:*:*:*:*
|
解决方案
中文解决方案:
英文解决方案:
临时解决方案:
参考链接
cve.org
CVSS评分详情
3.0 (cna)
HIGHCVSS:3.0/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
时间信息
利用信息
数据源详情
| 数据源 | 记录ID | 版本 | 提取时间 |
|---|---|---|---|
| CVE | cve_CVE-2019-12674 |
2025-11-11 15:20:00 | 2025-11-11 07:35:30 |
| NVD | nvd_CVE-2019-12674 |
2025-11-11 14:56:27 | 2025-11-11 07:44:03 |
| CNNVD | cnnvd_CNNVD-201910-088 |
2025-11-11 15:10:17 | 2025-11-11 07:54:58 |
版本与语言
安全公告
变更历史
查看详细变更
- vulnerability_type: 未提取 -> 其他
- cnnvd_id: 未提取 -> CNNVD-201910-088
- data_sources: ['cve', 'nvd'] -> ['cnnvd', 'cve', 'nvd']
查看详细变更
- affected_products_count: 1 -> 10
- data_sources: ['cve'] -> ['cve', 'nvd']