Cisco has identified a critical command injection vulnerability within its Firepower Threat Defence (FTD) devices. This security issue, designated as CVE-2023-20048, carries a high severity rating of 9.9 on the Common Vulnerability Scoring System (CVSS). It enables an authenticated remote attacker to execute unauthorized configuration commands on the target device’s management center software.
The vulnerability arises from insufficiently authorized configuration commands sent via the web service interface, with exploitation achieved through a crafted HTTP request. While Cisco hasn’t specified the exact commands that can be exploited, they have confirmed their potential risk.
Cisco has addressed this issue as part of a broader security update encompassing adaptive security appliance (ASA), Firepower management center (FMC), and FTD software. This update addresses a total of 27 vulnerabilities outlined in 22 advisories.
In addition to CVE-2023-20048, there are eight other vulnerabilities with high severity ratings:
- CVE-2023-20086: An IPv6 ICMP message that can force a device reload, resulting in a denial-of-service condition.
- CVE-2023-20095: Vulnerability in ASA’s and FTD’s VPN software that can be exploited using crafted HTTPS requests.
- CVE-2023-20244: A packet inspection flaw in the Firepower 2100 series firewalls.
- CVE-2023-20083: An IPv6 ICMP issue in FTD when configured with Snort 2.
- CVE-2023-20155: Lack of rate limiting in the FMC API, making it susceptible to exploitation by sending a high rate of HTTP requests.
Two additional vulnerabilities involve code injection:
- CVE-2023-20063: In FTD devices running FMC, it allows local attackers to run code as root.
- CVE-2023-20220: A pair of command injection vulnerabilities in FMC.
This comprehensive security update is essential for ensuring the protection of Cisco’s network devices and mitigating potential risks associated with these vulnerabilities.


