Loading HuntDB...

Cisco Firepower Extensible Operating System (FXOS)

101 Versions 9 CVEs

Versions

2.2.2.54

OTHER 4 CVEs

2.6.1.157

OTHER 3 CVEs

2.6.1.192

OTHER 3 CVEs

2.6.1.265

OTHER 1 CVE

2.11.1.205

OTHER 1 CVE

2.3.1.88

OTHER 4 CVEs

2.3.1.219

OTHER 3 CVEs

2.9.1.135

OTHER 3 CVEs

2.3.1.179

OTHER 3 CVEs

2.2.2.148

OTHER 3 CVEs

2.13.0.212

OTHER 1 CVE

2.11.1.200

OTHER 1 CVE

2.8.1.152

OTHER 3 CVEs

2.2.2.17

OTHER 4 CVEs

2.6.1.204

OTHER 3 CVEs

2.3.1.215

OTHER 3 CVEs

2.2.2.149

OTHER 3 CVEs

2.12.0.450

OTHER 2 CVEs

2.10.1.271

OTHER 1 CVE

2.12.1.29

OTHER 1 CVE

2.3.1.155

OTHER 3 CVEs

2.8.1.139

OTHER 3 CVEs

2.3.1.58

OTHER 4 CVEs

2.8.1.105

OTHER 3 CVEs

2.12.1.48

OTHER 1 CVE

2.6.1.239

OTHER 3 CVEs

2.3.1.230

OTHER 2 CVEs

2.10.1.159

OTHER 3 CVEs

2.10.1.207

OTHER 2 CVEs

2.2.2.26

OTHER 4 CVEs

2.3.1.99

OTHER 3 CVEs

2.3.1.180

OTHER 3 CVEs

2.6.1.166

OTHER 3 CVEs

2.12.0.432

OTHER 2 CVEs

2.8.1.190

OTHER 2 CVEs

2.2.2.83

OTHER 3 CVEs

2.6.1.224

OTHER 3 CVEs

2.3.1.190

OTHER 3 CVEs

2.9.1.131

OTHER 3 CVEs

2.2.1.66

OTHER 4 CVEs

2.6.1.214

OTHER 3 CVEs

2.3.1.91

OTHER 4 CVEs

2.3.1.173

OTHER 3 CVEs

2.3.1.166

OTHER 3 CVEs

2.8.1.125

OTHER 3 CVEs

2.6.1.131

OTHER 3 CVEs

2.6.1.187

OTHER 3 CVEs

2.8.1.162

OTHER 3 CVEs

2.2.2.86

OTHER 3 CVEs

2.3.1.144

OTHER 3 CVEs

2.3.1.110

OTHER 3 CVEs

2.6.1.254

OTHER 3 CVEs

2.2.2.19

OTHER 4 CVEs

2.3.1.145

OTHER 3 CVEs

2.12.0.467

OTHER 1 CVE

2.6.1.238

OTHER 3 CVEs

2.11.1.182

OTHER 2 CVEs

2.3.1.66

OTHER 4 CVEs

2.3.1.56

OTHER 4 CVEs

2.3.1.73

OTHER 4 CVEs

2.8.1.143

OTHER 3 CVEs

2.6.1.230

OTHER 3 CVEs

2.13.0.198

OTHER 2 CVEs

2.8.1.186

OTHER 2 CVEs

2.6.1.169

OTHER 3 CVEs

2.3.1.75

OTHER 4 CVEs

2.2

MAJOR_MINOR 1 CVE

2.3.1.216

OTHER 3 CVEs

2.12.0.498

OTHER 1 CVE

2.11.1.154

OTHER 3 CVEs

2.8.1.172

OTHER 3 CVEs

2.2.2.137

OTHER 3 CVEs

2.3.1.111

OTHER 3 CVEs

2.10.1.234

OTHER 2 CVEs

2.9.1.158

OTHER 3 CVEs

2.3.1.130

OTHER 3 CVEs

2.2.2.28

OTHER 4 CVEs

2.2.2.101

OTHER 3 CVEs

2.6.1.264

OTHER 1 CVE

2.2.2.71

OTHER 3 CVEs

2.9.1.143

OTHER 3 CVEs

2.13.0.243

OTHER 1 CVE

2.9.1.150

OTHER 3 CVEs

2.3.1.93

OTHER 4 CVEs

2.6.1.229

OTHER 3 CVEs

2.14.1.131

OTHER 1 CVE

unspecified

OTHER 4 CVEs

2.2.2.91

OTHER 3 CVEs

2.10.1.245

OTHER 1 CVE

2.6.1.259

OTHER 2 CVEs

2.2.2.24

OTHER 4 CVEs

2.2.2.97

OTHER 3 CVEs

2.8.1.164

OTHER 3 CVEs

2.2.2.60

OTHER 4 CVEs

2.12.0.31

OTHER 2 CVEs

2.10.1.179

OTHER 3 CVEs

2.8.1.198

OTHER 1 CVE

2.10.1.166

OTHER 3 CVEs

2.2.1.63

OTHER 4 CVEs

2.2.1.70

OTHER 4 CVEs

2.6.1.174

OTHER 3 CVEs

Recent CVEs

CVE-2024-20294

A vulnerability in the Link Layer Discovery Protocol (LLDP) feature of Cisco FXOS Software and Cisco NX-OS Software could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to improper handling of specific fields in an LLDP frame. An attacker could exploit this vulnerability by sending a crafted LLDP packet to an interface of an affected device and having an authenticated user retrieve LLDP statistics from the affected device through CLI show commands or Simple Network Management Protocol (SNMP) requests. A successful exploit could allow the attacker to cause the LLDP service to crash and stop running on the affected device. In certain situations, the LLDP crash may result in a reload of the affected device. Note: LLDP is a Layer 2 link protocol. To exploit this vulnerability, an attacker would need to be directly connected to an interface of an affected device, either physically or logically (for example, through a Layer 2 Tunnel configured to transport the LLDP protocol).

MEDIUM Feb 28, 2024

CVE-2023-20234

A vulnerability in the CLI of Cisco FXOS Software could allow an authenticated, local attacker to create a file or overwrite any file on the filesystem of an affected device, including system files. The vulnerability occurs because there is no validation of parameters when a specific CLI command is used. An attacker could exploit this vulnerability by authenticating to an affected device and using the command at the CLI. A successful exploit could allow the attacker to overwrite any file on the disk of the affected device, including system files. The attacker must have valid administrative credentials on the affected device to exploit this vulnerability.

MEDIUM Aug 23, 2023

CVE-2023-20200

A vulnerability in the Simple Network Management Protocol (SNMP) service of Cisco FXOS Software for Firepower 4100 Series and Firepower 9300 Security Appliances and of Cisco UCS 6300 Series Fabric Interconnects could allow an authenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to the improper handling of specific SNMP requests. An attacker could exploit this vulnerability by sending a crafted SNMP request to an affected device. A successful exploit could allow the attacker to cause the affected device to reload, resulting in a DoS condition. Note: This vulnerability affects all supported SNMP versions. To exploit this vulnerability through SNMPv2c or earlier, an attacker must know the SNMP community string that is configured on an affected device. To exploit this vulnerability through SNMPv3, the attacker must have valid credentials for an SNMP user who is configured on the affected device.

HIGH Aug 23, 2023

CVE-2022-20934

A vulnerability in the CLI of Cisco Firepower Threat Defense (FTD) Software and Cisco FXOS Software could allow an authenticated, local attacker to execute arbitrary commands on the underlying operating system as root. This vulnerability is due to improper input validation for specific CLI commands. An attacker could exploit this vulnerability by injecting operating system commands into a legitimate command. A successful exploit could allow the attacker to escape the restricted command prompt and execute arbitrary commands on the underlying operating system. To successfully exploit this vulnerability, an attacker would need valid Administrator credentials.

MEDIUM Nov 10, 2022