Firepower Extensible Operating System
Vendor:
First CVE: Jul 29, 2015 · Active for 10 years
56
Total CVEs
More Total CVEs than 98% of tracked products
5.6
Avg CVEs / Year
Higher CVE frequency than 90% of tracked products
6.8
Avg CVSS
Higher Avg CVSS than 39% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Firepower Extensible Operating System over time
Volume of CVEsAvg CVSS Base Score
First CVE
Jul 29, 2015
10 years ago
Most Recent CVE
Feb 29, 2024
876 days ago
CVE Severity & Scoring
Firepower Extensible Operating System56 CVEs
55%
39%
All CVEs352,294 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local25 (44.6%)
Network13 (23.2%)
Unknown9 (16.1%)
Physical0 (0.0%)
Adjacent Network9 (16.1%)
Attack Complexity
Low46 (82.1%)
High1 (1.8%)
Unknown9 (16.1%)
User Interaction
None45 (80.4%)
Unknown9 (16.1%)
Required2 (3.6%)
Privileges Required
Low14 (25.0%)
High13 (23.2%)
None20 (35.7%)
Unknown9 (16.1%)
Top CVEs
Signals from CVEs in this product scope (56 CVEs).
56 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2018-0310CRITICAL A vulnerability in the Cisco Fabric Services component of Cisco FXOS Software and Cisco NX-OS Software could allow an unauthenticated, remote attacker to obtain sensitive informati | Jun 21, 2018 | 9.8 | 32 | NO | NO |
CVE-2019-1858HIGH A vulnerability in the Simple Network Management Protocol (SNMP) input packet processor of Cisco FXOS Software and Cisco NX-OS Software could allow an unauthenticated, remote attac | May 16, 2019 | 8.6 | 28 | NO | NO |
CVE-2017-3883HIGH A vulnerability in the authentication, authorization, and accounting (AAA) implementation of Cisco Firepower Extensible Operating System (FXOS) and NX-OS System Software could allo | Oct 19, 2017 | 8.6 | 28 | NO | NO |
CVE-2021-1368HIGH A vulnerability in the Unidirectional Link Detection (UDLD) feature of Cisco FXOS Software and Cisco NX-OS Software could allow an unauthenticated, adjacent attacker to execute arb | Feb 24, 2021 | 8.8 | 27 | NO | NO |
CVE-2020-3517HIGH A vulnerability in the Cisco Fabric Services component of Cisco FXOS Software and Cisco NX-OS Software could allow an unauthenticated attacker to cause process crashes, which could | Aug 27, 2020 | 8.6 | 27 | NO | NO |
CVE-2015-6435CRITICAL An unspecified CGI script in Cisco FX-OS before 1.1.2 on Firepower 9000 devices and Cisco Unified Computing System (UCS) Manager before 2.2(4b), 2.2(5) before 2.2(5a), and 3.0 befo | Jan 22, 2016 | 9.8 | 27 | NO | NO |
CVE-2019-1597HIGH Multiple vulnerabilities in the implementation of the Lightweight Directory Access Protocol (LDAP) feature in Cisco FXOS Software and Cisco NX-OS Software could allow an unauthenti | Mar 7, 2019 | 7.5 | 26 | NO | NO |
CVE-2018-0303HIGH A vulnerability in the Cisco Discovery Protocol component of Cisco FXOS Software and Cisco NX-OS Software could allow an unauthenticated, adjacent attacker to execute arbitrary cod | Jun 21, 2018 | 8.8 | 26 | NO | NO |
CVE-2017-6600HIGH A vulnerability in the CLI of the Cisco Unified Computing System (UCS) Manager, Cisco Firepower 4100 Series Next-Generation Firewall (NGFW), and Cisco Firepower 9300 Security Appli | Apr 7, 2017 | 7.8 | 26 | NO | NO |
CVE-2019-1598HIGH Multiple vulnerabilities in the implementation of the Lightweight Directory Access Protocol (LDAP) feature in Cisco FXOS Software and Cisco NX-OS Software could allow an unauthenti | Mar 7, 2019 | 7.5 | 25 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (56 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (56 CVEs).
Media Mentions
Signals from CVEs in this product scope (56 CVEs).
Top CNAs Publishing CVEs For Firepower Extensible Operating System
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| r231 | 2 | 7.0 | 0.7% | 0 | 0 |
| 2.9.1.158 | 2 | 6.7 | 0.3% | 0 | 0 |
| 2.9.1.150 | 2 | 6.7 | 0.3% | 0 | 0 |
| 2.9.1.143 | 2 | 6.7 | 0.3% | 0 | 0 |
| 2.9.1.135 | 2 | 6.7 | 0.3% | 0 | 0 |
| 2.9.1.131 | 2 | 6.7 | 0.3% | 0 | 0 |
| 2.8.1.198 | 1 | 6.6 | 0.3% | 0 | 0 |
| 2.8.1.190 | 1 | 6.6 | 0.3% | 0 | 0 |
| 2.8.1.186 | 1 | 6.6 | 0.3% | 0 | 0 |
| 2.8.1.172 | 2 | 6.7 | 0.3% | 0 | 0 |
| 2.8.1.164 | 2 | 6.7 | 0.3% | 0 | 0 |
| 2.8.1.162 | 2 | 6.7 | 0.3% | 0 | 0 |
| 2.8.1.152 | 2 | 6.7 | 0.3% | 0 | 0 |
| 2.8.1.143 | 2 | 6.7 | 0.3% | 0 | 0 |
| 2.8.1.139 | 2 | 6.7 | 0.3% | 0 | 0 |
| 2.8.1.125 | 2 | 6.7 | 0.3% | 0 | 0 |
| 2.8.1.105 | 2 | 6.7 | 0.3% | 0 | 0 |
| 2.7.1.98 | 1 | 6.7 | 0.3% | 0 | 0 |
| 2.7.1.92 | 1 | 6.7 | 0.3% | 0 | 0 |
| 2.7.1.143 | 1 | 6.7 | 0.3% | 0 | 0 |