Vulnerabilities > Cisco > Firepower Extensible Operating System > 2.4

DATE CVE VULNERABILITY TITLE RISK
2022-02-23 CVE-2022-20625 Unspecified vulnerability in Cisco Firepower Extensible Operating System
A vulnerability in the Cisco Discovery Protocol service of Cisco FXOS Software and Cisco NX-OS Software could allow an unauthenticated, adjacent attacker to cause the service to restart, resulting in a denial of service (DoS) condition.
low complexity
cisco
4.3
2021-09-23 CVE-2021-34714 Improper Input Validation vulnerability in Cisco products
A vulnerability in the Unidirectional Link Detection (UDLD) feature of Cisco FXOS Software, Cisco IOS Software, Cisco IOS XE Software, Cisco IOS XR Software, and Cisco NX-OS Software could allow an unauthenticated, adjacent attacker to cause an affected device to reload.
low complexity
cisco CWE-20
7.4
2020-10-21 CVE-2020-3457 OS Command Injection vulnerability in Cisco products
A vulnerability in the CLI of Cisco FXOS Software could allow an authenticated, local attacker to inject arbitrary commands that are executed with root privileges.
local
low complexity
cisco CWE-78
6.7
2020-02-26 CVE-2020-3167 OS Command Injection vulnerability in Cisco products
A vulnerability in the CLI of Cisco FXOS Software and Cisco UCS Manager Software could allow an authenticated, local attacker to execute arbitrary commands on the underlying operating system (OS).
local
low complexity
cisco CWE-78
7.8
2020-02-26 CVE-2020-3166 Improper Input Validation vulnerability in Cisco products
A vulnerability in the CLI of Cisco FXOS Software could allow an authenticated, local attacker to read or write arbitrary files on the underlying operating system (OS).
local
low complexity
cisco CWE-20
6.7
2019-11-05 CVE-2019-1734 Unspecified vulnerability in Cisco Firepower Extensible Operating System and Nx-Os
A vulnerability in the implementation of a CLI diagnostic command in Cisco FXOS Software and Cisco NX-OS Software could allow an authenticated, local attacker to view sensitive system files that should be restricted.
local
low complexity
cisco
5.5
2019-05-15 CVE-2019-1795 Argument Injection or Modification vulnerability in Cisco Nx-Os
A vulnerability in the CLI of Cisco FXOS Software and Cisco NX-OS Software could allow an authenticated, local attacker to execute arbitrary commands on the underlying Linux operating system with the privilege level of root.
local
low complexity
cisco CWE-88
6.7