A vulnerability in Cisco Firepower Threat Defense (FTD) Software for Cisco Firepower 1000, 2100, 3100, and 4200 Series could allow an unauthenticated, local attacker to access an affected system using static credentials. This vulnerability is due to the presence of static accounts with hard-coded passwords on an affected system. An attacker could exploit this vulnerability by logging in to the CLI of an affected device with these credentials. A successful exploit could allow the attacker to access the affected system and retrieve sensitive information, perform limited troubleshooting actions, modify some configuration options, or render the device unable to boot to the operating system, requiring a reimage of the device.
The system contains accounts with hard-coded passwords that cannot be changed by the administrator in the standard way. An attacker with local access (physical or through console) can use these static credentials to log in via the device's CLI. Upon successful login, they gain access to the system without needing any privileges or user interaction.
An attacker can read sensitive information, perform limited diagnostic actions, modify selected configuration options, or cause the device's operating system to become unable to boot — requiring reimage. The impact may include breach of confidentiality, integrity, and availability of the device.
Apply patches available from the vendor according to the references: https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ftd-statcred-dFC8tXT5. Additionally, it is recommended to restrict physical access to devices and console port access exclusively to authorized personnel.
Cisco Firepower Threat Defense (FTD) Software installed on Cisco Firepower 1000, 2100, 3100, and 4200 series devices. Specific software versions are indicated in the vendor's references.
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:HCisco Firepower 1000
HWCiscoall versionsCisco Firepower 1010
HWCiscoall versionsCisco Firepower 1020
HWCiscoall versionsCisco Firepower 1030
HWCiscoall versionsCisco Firepower 1040
HWCiscoall versionsCisco Firepower 1120
HWCiscoall versionsCisco Firepower 1140
HWCiscoall versionsCisco Firepower 1150
HWCiscoall versionsCisco Firepower 2100
HWCiscoall versionsCisco Firepower 2110
HWCiscoall versionsCisco Firepower 2120
HWCiscoall versionsCisco Firepower 2130
HWCiscoall versionsCisco Firepower 2140
HWCiscoall versionsCisco Firepower 3105
HWCiscoall versionsCisco Firepower 3110
HWCiscoall versionsCisco Firepower 3120
HWCiscoall versionsCisco Firepower 3130
HWCiscoall versionsCisco Firepower 3140
HWCiscoall versionsCisco Firepower 4215
HWCiscoall versionsCisco Firepower 4225
HWCiscoall versionsCisco Firepower 4245
HWCiscoall versionsCisco Secure Firewall Threat Defense
APPCisco7.1.07.1.0.17.1.0.27.1.0.37.2.07.2.0.17.2.17.2.27.2.37.2.47.2.4.17.2.57.2.5.17.2.5.27.2.6+ 8 more
Related vulnerabilities
RCE jako root w Cisco ASA i FTD poprzez podatny serwer VPN web
RCE w web services Cisco ASA, FTD, IOS, IOS XE, IOS XR przez HTTP
Cisco ASA – brak walidacji autentyczności obrazu ASDM umożliwia RCE
Path Traversal w Cisco ASA i FTD — nieautoryzowany dostęp do plików przez WebVPN/AnyConnect
Cisco ASA SSL VPN — double free umożliwiający RCE lub DoS