CRITICAL✓ PATCH🇵🇱 Wersja polska

CVE-2024-20412

CVSS 9.3v3.1pub. 2024-10-23upd. 2026-08-11

A vulnerability in Cisco Firepower Threat Defense (FTD) Software for Cisco Firepower 1000, 2100, 3100, and 4200 Series could allow an unauthenticated, local attacker to access an affected system using static credentials. This vulnerability is due to the presence of static accounts with hard-coded passwords on an affected system. An attacker could exploit this vulnerability by logging in to the CLI of an affected device with these credentials. A successful exploit could allow the attacker to access the affected system and retrieve sensitive information, perform limited troubleshooting actions, modify some configuration options, or render the device unable to boot to the operating system, requiring a reimage of the device.

🤖 AI Analysis
How it works

The system contains accounts with hard-coded passwords that cannot be changed by the administrator in the standard way. An attacker with local access (physical or through console) can use these static credentials to log in via the device's CLI. Upon successful login, they gain access to the system without needing any privileges or user interaction.

Impact

An attacker can read sensitive information, perform limited diagnostic actions, modify selected configuration options, or cause the device's operating system to become unable to boot — requiring reimage. The impact may include breach of confidentiality, integrity, and availability of the device.

Mitigation & patch

Apply patches available from the vendor according to the references: https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ftd-statcred-dFC8tXT5. Additionally, it is recommended to restrict physical access to devices and console port access exclusively to authorized personnel.

Who is affected

Cisco Firepower Threat Defense (FTD) Software installed on Cisco Firepower 1000, 2100, 3100, and 4200 series devices. Specific software versions are indicated in the vendor's references.

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
  • Cisco Firepower 1000

    HW
    Cisco
    all versions
  • Cisco Firepower 1010

    HW
    Cisco
    all versions
  • Cisco Firepower 1020

    HW
    Cisco
    all versions
  • Cisco Firepower 1030

    HW
    Cisco
    all versions
  • Cisco Firepower 1040

    HW
    Cisco
    all versions
  • Cisco Firepower 1120

    HW
    Cisco
    all versions
  • Cisco Firepower 1140

    HW
    Cisco
    all versions
  • Cisco Firepower 1150

    HW
    Cisco
    all versions
  • Cisco Firepower 2100

    HW
    Cisco
    all versions
  • Cisco Firepower 2110

    HW
    Cisco
    all versions
  • Cisco Firepower 2120

    HW
    Cisco
    all versions
  • Cisco Firepower 2130

    HW
    Cisco
    all versions
  • Cisco Firepower 2140

    HW
    Cisco
    all versions
  • Cisco Firepower 3105

    HW
    Cisco
    all versions
  • Cisco Firepower 3110

    HW
    Cisco
    all versions
  • Cisco Firepower 3120

    HW
    Cisco
    all versions
  • Cisco Firepower 3130

    HW
    Cisco
    all versions
  • Cisco Firepower 3140

    HW
    Cisco
    all versions
  • Cisco Firepower 4215

    HW
    Cisco
    all versions
  • Cisco Firepower 4225

    HW
    Cisco
    all versions
  • Cisco Firepower 4245

    HW
    Cisco
    all versions
  • Cisco Secure Firewall Threat Defense

    APP
    Cisco
    7.1.07.1.0.17.1.0.27.1.0.37.2.07.2.0.17.2.17.2.27.2.37.2.47.2.4.17.2.57.2.5.17.2.5.27.2.6+ 8 more
🟢
PATCH AVAILABLE
Vendor update available. Deploy in standard maintenance cycle.
CWE
References

Related vulnerabilities

CVE-2025-20333CRITICAL9.9⚠ KEVPL ✓same product

RCE jako root w Cisco ASA i FTD poprzez podatny serwer VPN web

CVE-2025-20363CRITICAL9.0PL ✓same product

RCE w web services Cisco ASA, FTD, IOS, IOS XE, IOS XR przez HTTP

CVE-2022-20829CRITICAL9.1PL ✓same product

Cisco ASA – brak walidacji autentyczności obrazu ASDM umożliwia RCE

CVE-2020-3187CRITICAL9.1PL ✓same product

Path Traversal w Cisco ASA i FTD — nieautoryzowany dostęp do plików przez WebVPN/AnyConnect

CVE-2018-0101CRITICAL10.0PL ✓same product

Cisco ASA SSL VPN — double free umożliwiający RCE lub DoS