CNNVD-202508-1690 Information

CNNVD ID

CNNVD-202508-1690

CVE-2025-20220

  • CNNVD Published: 2025-08-14

Description (Chinese)

Cisco Secure Firewall Management Center和Cisco Secure Firewall Threat Defense都是美国思科(Cisco)公司的产品。Cisco Secure Firewall Management Center是一个强大的网络安全管理工具。Cisco Secure Firewall Threat Defense是一个集成式防火墙平台。 Cisco Secure Firewall Management Center和Cisco Secure Firewall Threat Defense存在操作系统命令注入漏洞,该漏洞源于CLI命令输入验证不足,可能导致执行任意命令。

Description (English)

Cisco Security Firewall Management Center and Cisco Security Firewall. Cisco Security Fairwall Management Center is a powerful cybersecurity management tool. Cisco Security Firewall Threat Defense is an integrated firewall platform. Cisco Security Firewall Management Center and Cisco Security Firewall Threat Defense had an operational system command leak, which stemmed from the lack of sufficient input validation of the CLI order, which could lead to the execution of arbitrary orders.

Hazard Level

High

Vulnerability Type

操作系统命令注入

Affected Vendor

思科

Published

2025-08-14

Last Modified

2026-02-24

References

https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-fmc-ftd-cmdinj-PhE7kmT https://nvd.nist.gov/vuln/detail/CVE-2025-20220

Patch

https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-fmc-ftd-cmdinj-PhE7kmT

Share on: