PT-2026-98407 · Cisco+1 · Firesight Manager+1

·

CVE-2026-97863

·

Published

2026-09-25

·

Updated

2026-09-25

CVSS v4.0

6.3

Medium

VectorAV:N/AC:L/AT:N/PR:L/UI:A/VC:N/VI:N/VA:N/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions misp-modules (affected versions not specified)
Description The cisco firesight manager ACL rule export module generates a shell script (.sh) that authenticates to and calls the Cisco fireSIGHT Manager API. The module interpolates configuration values and MISP attribute values—such as destination IPs, URLs, and event info comments—directly into single-quoted shell string assignments without escaping or sanitization. An attacker can inject arbitrary shell commands by submitting MISP events or attributes containing a single-quote character, which breaks the quoting context. A security analyst executing the resulting script would run these commands with their own privileges, potentially compromising their workstation or exposing fireSIGHT Manager credentials. Additionally, the module contains a defect where the config variable is referenced unconditionally despite being assigned only within a conditional block, leading to a NameError and causing a denial of service when the request payload lacks a config key.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

DoS

OS Command Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-97863

Affected Products

Firesight Manager
Misp-Modules