Early Access — Mondoo Vulnerability Intelligence is currently in preview.
An authenticated admin user with access to both the management WebUI and command line interface on a Firebox can enable a diagnostic debug shell by uploading a platform and version-specific diagnostic package and executing a leftover diagnostic command.
This issue affects Fireware OS: from 12.0 before 12.11.2.
Exploitability
AV:NAC:LAT:PPR:HUI:NVulnerable System
VC:HVI:HVA:HSubsequent System
SC:HSI:HSA:H8.9/CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:HOther