CVE-2021-1518
A vulnerability in the REST API of Cisco Firepower Device Manager (FDM) On-Box Software could allow an authenticated, remote attacker to execute arbitrary code on the underlying operating system of an affected device. This vulnerability is due to insufficient sanitization of user input on specific REST API commands. An attacker could exploit this vulnerability by sending a crafted HTTP request to the API subsystem of an affected device. A successful exploit could allow the attacker to execute arbitrary code on the underlying operating system. To exploit this vulnerability, an attacker would need valid low-privileged user credentials.
EPSS 1.87% · 77.3th percentile
Risk Scores
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| cisco | firepower_device_manager_on-box | 6.3.0, 6.5.0 |
| Cisco | Cisco Firepower Threat Defense Software | n/a |
Timeline
- Jul 22, 2021 CVE Published
- Jul 23, 2021 EPSS Score
- Sep 20, 2021 EPSS Score
- Nov 19, 2021 EPSS Score
- Jan 17, 2022 EPSS Score
- Feb 4, 2022 EPSS Score
- Mar 18, 2022 EPSS Score
- Apr 1, 2022 EPSS Score
- May 16, 2022 EPSS Score
- Sep 13, 2022 EPSS Score
- Nov 11, 2022 EPSS Score
- Jan 9, 2023 EPSS Score