cisco firepower-device-manager-on-box CVE-2020-3309 is a vulnerability in Cisco Firepower Device Manager On Box
Published on May 6, 2020

Cisco Firepower Device Manager On-Box Software Arbitrary File Overwrite Vulnerability
A vulnerability in Cisco Firepower Device Manager (FDM) On-Box software could allow an authenticated, remote attacker to overwrite arbitrary files on the underlying operating system of an affected device. The vulnerability is due to improper input validation. An attacker could exploit this vulnerability by uploading a malicious file to an affected device. A successful exploit could allow the attacker to overwrite arbitrary files on as well as modify the underlying operating system of an affected device.

Vendor Advisory NVD

Weakness Type

Improper Input Validation

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.


Products Associated with CVE-2020-3309

You can be notified by email with stack.watch whenever vulnerabilities like CVE-2020-3309 are published in Cisco Firepower Device Manager On Box:

 

Affected Versions

Cisco Firepower Threat Defense Software Version n/a is affected by CVE-2020-3309

Exploit Probability

EPSS
0.88%
Percentile
74.98%

EPSS (Exploit Prediction Scoring System) scores estimate the probability that a vulnerability will be exploited in the wild within the next 30 days. The percentile shows you how this score compares to all other vulnerabilities.