Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2024-20412


A vulnerability in Cisco Firepower Threat Defense (FTD) Software for Cisco Firepower 1000, 2100, 3100, and 4200 Series could allow an unauthenticated, local attacker to access an affected system using static credentials. This vulnerability is due to the presence of static accounts with hard-coded passwords on an affected system. An attacker could exploit this vulnerability by logging in to the CLI of an affected device with these credentials. A successful exploit could allow the attacker to access the affected system and retrieve sensitive information, perform limited troubleshooting actions, modify some configuration options, or render the device unable to boot to the operating system, requiring a reimage of the device.


Published

2024-10-23T18:15:09.430

Last Modified

2024-11-05T15:03:34.777

Status

Analyzed

Source

[email protected]

Severity

CVSSv3.1: 9.3 (CRITICAL)

Weaknesses
  • Type: Secondary
    CWE-259
  • Type: Primary
    CWE-798

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application cisco firepower_threat_defense 7.1.0 Yes
Application cisco firepower_threat_defense 7.1.0.1 Yes
Application cisco firepower_threat_defense 7.1.0.2 Yes
Application cisco firepower_threat_defense 7.1.0.3 Yes
Application cisco firepower_threat_defense 7.2.0 Yes
Application cisco firepower_threat_defense 7.2.0.1 Yes
Application cisco firepower_threat_defense 7.2.1 Yes
Application cisco firepower_threat_defense 7.2.2 Yes
Application cisco firepower_threat_defense 7.2.3 Yes
Application cisco firepower_threat_defense 7.2.4 Yes
Application cisco firepower_threat_defense 7.2.4.1 Yes
Application cisco firepower_threat_defense 7.2.5 Yes
Application cisco firepower_threat_defense 7.2.5.1 Yes
Application cisco firepower_threat_defense 7.2.5.2 Yes
Application cisco firepower_threat_defense 7.2.6 Yes
Application cisco firepower_threat_defense 7.2.7 Yes
Application cisco firepower_threat_defense 7.3.0 Yes
Application cisco firepower_threat_defense 7.3.1 Yes
Application cisco firepower_threat_defense 7.3.1.1 Yes
Application cisco firepower_threat_defense 7.3.1.2 Yes
Application cisco firepower_threat_defense 7.4.0 Yes
Application cisco firepower_threat_defense 7.4.1 Yes
Application cisco firepower_threat_defense 7.4.1.1 Yes
Hardware cisco firepower_1000 - No
Hardware cisco firepower_1010 - No
Hardware cisco firepower_1020 - No
Hardware cisco firepower_1030 - No
Hardware cisco firepower_1040 - No
Hardware cisco firepower_1120 - No
Hardware cisco firepower_1140 - No
Hardware cisco firepower_1150 - No
Hardware cisco firepower_2100 - No
Hardware cisco firepower_2110 - No
Hardware cisco firepower_2120 - No
Hardware cisco firepower_2130 - No
Hardware cisco firepower_2140 - No
Hardware cisco firepower_3105 - No
Hardware cisco firepower_3110 - No
Hardware cisco firepower_3120 - No
Hardware cisco firepower_3130 - No
Hardware cisco firepower_3140 - No
Hardware cisco firepower_4215 - No
Hardware cisco firepower_4225 - No
Hardware cisco firepower_4245 - No

References