CVE-2020-3167 is a command injection vulnerability in the CLI of Cisco FXOS Software and Cisco UCS Manager Software, allowing an authenticated, local attacker to execute arbitrary OS commands. The vulnerability stems from insufficient input validation, enabling an attacker to inject crafted arguments into specific commands. This flaw carries a CVSSv3 score of 7.8 (High), indicating that a low-privileged local attacker can achieve high impact on confidentiality, integrity, and availability, with root privileges on Cisco UCS 6400 Series Fabric Interconnects. While there is no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB) is currently unavailable, and community discussion is limited.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 6.2.2, < 6.2.3.13CPE matchmatch criteria | cpe:2.3:a:cisco:firepower_threat_defense:*:*:*:*:*:*:*:* | ||
>= 6.3.0, < 6.4.0.8CPE matchmatch criteria | cpe:2.3:a:cisco:firepower_threat_defense:*:*:*:*:*:*:*:* | ||
>= 6.5.0, < 6.5.0.2CPE matchmatch criteria | cpe:2.3:a:cisco:firepower_threat_defense:*:*:*:*:*:*:*:* | ||
>= 9.8, < 9.9.2.66CPE matchmatch criteria | cpe:2.3:o:cisco:adaptive_security_appliance_software:*:*:*:*:*:*:*:* | ||
>= 9.10, < 9.12.3.6CPE matchmatch criteria | cpe:2.3:o:cisco:adaptive_security_appliance_software:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.