← Retour
CVE-2019-12675
high
CVSS 8.8
Multiple vulnerabilities in the multi-instance feature of Cisco Firepower Threat Defense (FTD) Software could allow an authenticated, local attacker to escape the container for their FTD instance and...
Résumé
Multiple vulnerabilities in the multi-instance feature of Cisco Firepower Threat Defense (FTD) Software could allow an authenticated, local attacker to escape the container for their FTD instance and execute commands with root privileges in the host namespace. These vulnerabilities are due to insuff...
Résumé IA openai / gpt-4o
Une vulnérabilité référencée **CVE-2019-12675** a été découverte dans cisco.
L'exploitation peut entraîner la prise de contrôle totale du système. Score CVSS : 8.8/10.
Action : appliquez le correctif officiel de l'éditeur.
En cas de doute, contactez votre service informatique ou cherchez « cisco CVE-2019-12675 » sur le site de l'éditeur.
CVE-2019-12675 (cisco) — CWE-216 / CVSS v3 8.8
Vecteur d'attaque : local / sans interaction utilisateur
Plan : 1) Audit SBOM, 2) Mise à jour staging→prod, 3) Surveillance WAF/proxy sur les endpoints affectés, 4) Recherche d'IOC dans les logs.
Réfs : voir GHSA / avis éditeur / version corrigée liés sur cette page.
❓ Quel est le problème
Cisco FTDソフトウェアのマルチインスタンス機能におけるコンテナ逃避の脆弱性。
📍 Périmètre concerné
Cisco Firepower Threat Defense (FTD) ソフトウェア
🔥 Gravité
ローカル攻撃者がホストの名前空間でルート権限を取得する可能性があるため、重大な脆弱性です。
🔧 Comment corriger
Ciscoから提供されたパッチを適用してください。
🛡️ Contournement
情報なし
🔍 Détection
ファイルシステムの変更やFTDインスタンスのコンテナ外の活動を監視します。