Positive Technologies IDs Cisco Vulnerability That Allowed C

Positive Technologies IDs Cisco Vulnerability That Allowed Criminals to Remotely Execute Arbitrary Code & Control Firewall


Positive Technologies IDs Cisco Vulnerability That Allowed Criminals to Remotely Execute Arbitrary Code & Control Firewall
Users are advised to install new versions of Cisco FDM On-Box, and check for signs of penetration using NTA and SIEM systems.
August 02, 2021
PDF
August 2, 2021 – Positive Technologies researchers, Nikita Abramov and Mikhail Klyuchnikov have discovered a vulnerability in Cisco Firepower Device Manager (FDM) On-Box – a product designed to locally configure Cisco Firepower NGFW firewalls – that could have allowed attackers to control a device. According to Forrester Research, Cisco is a recognized leader in the corporate firewall market. The flaw has been patched.
Vulnerability CVE-2021-1518 gained the CVSS 3.1. score of 6.3. The flaw was discovered in REST API[1] of Cisco FDM On-Box software, and allowed an authenticated remote attacker to execute arbitrary code in the operating system of an affected device.

Related Keywords

Nikita Abramov , Mikhail Klyuchnikov , Forrester Research , Pt Network Attack Discovery , Positive Technologies , Cisco Firepower Device Manager , Cisco Firepower , Attack Discovery , நிகிதா , ஃபாரெஸ்டர் ஆராய்ச்சி , ட் வலைப்பின்னல் தாக்குதல் கண்டுபிடிப்பு , பாஸிடிவ் தொழில்நுட்பங்கள் , சிஸ்கோ ஃபயர்பவரை , தாக்குதல் கண்டுபிடிப்பு ,

© 2025 Vimarsana