Firepower Extensible Operating System

Vendor:

First CVE: Jul 29, 2015 · Active for 10 years

56
Total CVEs
More Total CVEs than 98% of tracked products
5.6
Avg CVEs / Year
Higher CVE frequency than 90% of tracked products
6.8
Avg CVSS
Higher Avg CVSS than 39% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact Firepower Extensible Operating System over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jul 29, 2015
10 years ago
Most Recent CVE
Feb 29, 2024
876 days ago

CVE Severity & Scoring

Firepower Extensible Operating System56 CVEs
All CVEs352,294 CVEs
LowMediumHighCritical
Attack Vector
Local25 (44.6%)
Network13 (23.2%)
Unknown9 (16.1%)
Physical0 (0.0%)
Adjacent Network9 (16.1%)
Attack Complexity
Low46 (82.1%)
High1 (1.8%)
Unknown9 (16.1%)
User Interaction
None45 (80.4%)
Unknown9 (16.1%)
Required2 (3.6%)
Privileges Required
Low14 (25.0%)
High13 (23.2%)
None20 (35.7%)
Unknown9 (16.1%)

Top CVEs

Signals from CVEs in this product scope (56 CVEs).

56 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
A vulnerability in the Cisco Fabric Services component of Cisco FXOS Software and Cisco NX-OS Software could allow an unauthenticated, remote attacker to obtain sensitive informati
Jun 21, 20189.832NONO
A vulnerability in the Simple Network Management Protocol (SNMP) input packet processor of Cisco FXOS Software and Cisco NX-OS Software could allow an unauthenticated, remote attac
May 16, 20198.628NONO
A vulnerability in the authentication, authorization, and accounting (AAA) implementation of Cisco Firepower Extensible Operating System (FXOS) and NX-OS System Software could allo
Oct 19, 20178.628NONO
A vulnerability in the Unidirectional Link Detection (UDLD) feature of Cisco FXOS Software and Cisco NX-OS Software could allow an unauthenticated, adjacent attacker to execute arb
Feb 24, 20218.827NONO
A vulnerability in the Cisco Fabric Services component of Cisco FXOS Software and Cisco NX-OS Software could allow an unauthenticated attacker to cause process crashes, which could
Aug 27, 20208.627NONO
An unspecified CGI script in Cisco FX-OS before 1.1.2 on Firepower 9000 devices and Cisco Unified Computing System (UCS) Manager before 2.2(4b), 2.2(5) before 2.2(5a), and 3.0 befo
Jan 22, 20169.827NONO
Multiple vulnerabilities in the implementation of the Lightweight Directory Access Protocol (LDAP) feature in Cisco FXOS Software and Cisco NX-OS Software could allow an unauthenti
Mar 7, 20197.526NONO
A vulnerability in the Cisco Discovery Protocol component of Cisco FXOS Software and Cisco NX-OS Software could allow an unauthenticated, adjacent attacker to execute arbitrary cod
Jun 21, 20188.826NONO
A vulnerability in the CLI of the Cisco Unified Computing System (UCS) Manager, Cisco Firepower 4100 Series Next-Generation Firewall (NGFW), and Cisco Firepower 9300 Security Appli
Apr 7, 20177.826NONO
Multiple vulnerabilities in the implementation of the Lightweight Directory Access Protocol (LDAP) feature in Cisco FXOS Software and Cisco NX-OS Software could allow an unauthenti
Mar 7, 20197.525NONO

Exploit Exposure

Signals from CVEs in this product scope (56 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

Signals from CVEs in this product scope (56 CVEs).

Media Mentions

Signals from CVEs in this product scope (56 CVEs).

Top CNAs Publishing CVEs For Firepower Extensible Operating System

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
r23127.00.7%00
2.9.1.15826.70.3%00
2.9.1.15026.70.3%00
2.9.1.14326.70.3%00
2.9.1.13526.70.3%00
2.9.1.13126.70.3%00
2.8.1.19816.60.3%00
2.8.1.19016.60.3%00
2.8.1.18616.60.3%00
2.8.1.17226.70.3%00
2.8.1.16426.70.3%00
2.8.1.16226.70.3%00
2.8.1.15226.70.3%00
2.8.1.14326.70.3%00
2.8.1.13926.70.3%00
2.8.1.12526.70.3%00
2.8.1.10526.70.3%00
2.7.1.9816.70.3%00
2.7.1.9216.70.3%00
2.7.1.14316.70.3%00