CVE-2020-3167
Cisco Adaptive Security Appliance (ASA) vulnerability analysis and mitigation

Overview

A command injection vulnerability (CVE-2020-3167) was discovered in the Command Line Interface (CLI) of Cisco FXOS Software and Cisco UCS Manager Software. The vulnerability was disclosed on February 26, 2020, affecting multiple Cisco platforms including Firepower 1000 Series, Firepower 2100 Series, Firepower 4100 Series, Firepower 9300 Security Appliances, and UCS 6200 Series devices (NVD, Cisco ERP).

Technical details

The vulnerability stems from insufficient input validation in the CLI interface. This security flaw allows authenticated, local attackers to execute arbitrary commands on the underlying operating system by including crafted arguments to specific commands. The vulnerability has been assigned a CVSS score of 7.8 (High severity). On most affected platforms, the commands are executed with the privileges of the logged-in user, except for Cisco UCS 6400 Series Fabric Interconnects where the commands are executed with root privileges (CVE Mitre).

Impact

The successful exploitation of this vulnerability could allow an authenticated, local attacker to execute arbitrary commands on the underlying operating system. The impact is particularly severe for Cisco UCS 6400 Series Fabric Interconnects, where the injected commands are executed with root privileges, potentially leading to complete system compromise (NVD).

Mitigation and workarounds

Cisco has addressed this vulnerability through software updates. Users are advised to update their affected systems to the latest software version that contains the fix (Cisco Advisory).

Additional resources


SourceThis report was generated using AI

Related Cisco Adaptive Security Appliance (ASA) vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2025-20333CRITICAL9.9
  • Cisco Adaptive Security Appliance (ASA)Cisco Adaptive Security Appliance (ASA)
  • cpe:2.3:a:cisco:firepower_threat_defense
YesYesSep 25, 2025
CVE-2025-20363CRITICAL9
  • Cisco Adaptive Security Appliance (ASA)Cisco Adaptive Security Appliance (ASA)
  • cpe:2.3:a:cisco:firepower_threat_defense
NoYesSep 25, 2025
CVE-2025-20362HIGH8.6
  • Cisco Adaptive Security Appliance (ASA)Cisco Adaptive Security Appliance (ASA)
  • cpe:2.3:a:cisco:firepower_threat_defense
YesYesSep 25, 2025
CVE-2025-20263HIGH8.6
  • Cisco Adaptive Security Appliance (ASA)Cisco Adaptive Security Appliance (ASA)
  • cpe:2.3:a:cisco:firepower_threat_defense
NoYesAug 14, 2025
CVE-2025-20254MEDIUM5.8
  • Cisco Adaptive Security Appliance (ASA)Cisco Adaptive Security Appliance (ASA)
  • cpe:2.3:a:cisco:firepower_threat_defense
NoYesAug 14, 2025

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management