Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2019-15992


A vulnerability in the implementation of the Lua interpreter integrated in Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an authenticated, remote attacker to execute arbitrary code with root privileges on the underlying Linux operating system of an affected device. The vulnerability is due to insufficient restrictions on the allowed Lua function calls within the context of user-supplied Lua scripts. A successful exploit could allow the attacker to trigger a heap overflow condition and execute arbitrary code with root privileges on the underlying Linux operating system of an affected device.


Published

2020-09-23T01:15:13.333

Last Modified

2024-11-26T16:09:02.407

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 7.2 (HIGH)

CVSSv2 Vector

AV:N/AC:L/Au:S/C:C/I:C/A:C

  • Access Vector: NETWORK
  • Access Complexity: LOW
  • Authentication: SINGLE
  • Confidentiality Impact: COMPLETE
  • Integrity Impact: COMPLETE
  • Availability Impact: COMPLETE
Exploitability Score

8.0

Impact Score

10.0

Weaknesses
  • Type: Secondary
    CWE-119
  • Type: Primary
    CWE-787

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application cisco adaptive_security_appliance < 9.6.4.36 Yes
Operating System cisco adaptive_security_appliance_software < 9.8.4.15 Yes
Operating System cisco adaptive_security_appliance_software < 9.9.2.61 Yes
Operating System cisco adaptive_security_appliance_software < 9.10.1.32 Yes
Operating System cisco adaptive_security_appliance_software < 9.12.3 Yes
Operating System cisco adaptive_security_appliance_software < 9.13.1.4 Yes
Operating System cisco adaptive_security_appliance_software < 9.14.2.7 Yes
Operating System cisco adaptive_security_appliance_software < 9.15.1.4 Yes
Application cisco secure_firewall_management_center < 6.2.3.16 Yes
Application cisco secure_firewall_management_center < 6.3.0.6 Yes
Application cisco secure_firewall_management_center < 6.4.0.7 Yes
Application cisco secure_firewall_management_center < 6.5.0.2 Yes
Application cisco firepower_threat_defense - Yes

References