PT-2026-98407 · Cisco+1 · Firesight Manager+1
CVSS v4.0
6.3
Medium
| Vector | AV:N/AC:L/AT:N/PR:L/UI:A/VC:N/VI:N/VA:N/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X |
Name of the Vulnerable Software and Affected Versions
misp-modules (affected versions not specified)
Description
The
cisco firesight manager ACL rule export module generates a shell script (.sh) that authenticates to and calls the Cisco fireSIGHT Manager API. The module interpolates configuration values and MISP attribute values—such as destination IPs, URLs, and event info comments—directly into single-quoted shell string assignments without escaping or sanitization. An attacker can inject arbitrary shell commands by submitting MISP events or attributes containing a single-quote character, which breaks the quoting context. A security analyst executing the resulting script would run these commands with their own privileges, potentially compromising their workstation or exposing fireSIGHT Manager credentials. Additionally, the module contains a defect where the config variable is referenced unconditionally despite being assigned only within a conditional block, leading to a NameError and causing a denial of service when the request payload lacks a config key.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
DoS
OS Command Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Firesight Manager
Misp-Modules