Executive brief
Cisco Secure Firewall Threat Defense (FTD) is a network security appliance that protects enterprise networks. Authenticated administrators or local users with valid credentials can exploit insufficient input validation in the CLI to execute arbitrary commands as root, potentially compromising the entire security appliance and the network it protects.
Technical details
This vulnerability is a command injection flaw in the CLI feature of Cisco Secure FTD Software, arising from insufficient input validation of user-supplied command arguments. An authenticated local attacker with valid administrative credentials can submit crafted input to a specific CLI command, allowing arbitrary command execution on the underlying operating system with root privileges. Attack vector is local (AV:L) and requires low-level privilege (PR:L). The impact scope is changed (S:C), affecting availability (A:H) of the system. Cisco has released software updates addressing this vulnerability; no workarounds are available.
Affected products
- Cisco Secure Firewall Threat Defense
Timeline
- 2026-03-04: disclosed: Cisco Security Advisory published