← Back
Network Infrastructure
CVE-2019-12675 high CVSS 8.8

Multiple vulnerabilities in the multi-instance feature of Cisco Firepower Threat Defense (FTD) Software could allow an authenticated, local attacker to escape the container for their FTD instance and...

Summary

Multiple vulnerabilities in the multi-instance feature of Cisco Firepower Threat Defense (FTD) Software could allow an authenticated, local attacker to escape the container for their FTD instance and execute commands with root privileges in the host namespace. These vulnerabilities are due to insuff...

AI summary openai / gpt-4o

Cisco Firepower Threat Defense (FTD) ソフトウェアのマルチインスタンス機能における複数の脆弱性により、認証されたローカルの攻撃者がFTDインスタンスのコンテナを脱出し、ホストの名前空間でルート権限を持つコマンドを実行できる可能性があります。これらの脆弱性は、ファイルシステムの保護が不十分であることが原因です。
❓ What is the problem
Cisco FTDソフトウェアのマルチインスタンス機能におけるコンテナ逃避の脆弱性。
📍 Affected scope
Cisco Firepower Threat Defense (FTD) ソフトウェア
🔥 Severity
ローカル攻撃者がホストの名前空間でルート権限を取得する可能性があるため、重大な脆弱性です。
🔧 How to fix
Ciscoから提供されたパッチを適用してください。
🛡️ Workaround
情報なし
🔍 Detection
ファイルシステムの変更やFTDインスタンスのコンテナ外の活動を監視します。

References

🍪 About cookies

We use cookies to keep you logged in, remember your language, and improve the service.

Details →