Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2018-0254


A vulnerability in the detection engine of Cisco Firepower System Software could allow an unauthenticated, remote attacker to bypass configured file action policies if an Intelligent Application Bypass (IAB) with a drop percentage threshold is also configured. The vulnerability is due to incorrect counting of the percentage of dropped traffic. An attacker could exploit this vulnerability by sending network traffic to a targeted device. An exploit could allow the attacker to bypass configured file action policies, and traffic that should be dropped could be allowed into the network. Cisco Bug IDs: CSCvf86435.


Published

2018-04-19T20:29:01.127

Last Modified

2024-11-21T03:37:49.460

Status

Modified

Source

[email protected]

Severity

CVSSv3.0: 5.3 (MEDIUM)

CVSSv2 Vector

AV:N/AC:L/Au:N/C:N/I:P/A:N

  • Access Vector: NETWORK
  • Access Complexity: LOW
  • Authentication: NONE
  • Confidentiality Impact: NONE
  • Integrity Impact: PARTIAL
  • Availability Impact: NONE
Exploitability Score

10.0

Impact Score

2.9

Weaknesses
  • Type: Secondary
    CWE-693
  • Type: Primary
    CWE-693

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application cisco firepower_threat_defense 6.1.0.5 Yes
Application cisco firepower_threat_defense 6.2.0.2 Yes
Application cisco firepower_threat_defense 6.2.1 Yes
Application cisco firepower_threat_defense 6.2.2 Yes
Hardware cisco amp_7150 - No
Hardware cisco amp_8150 - No
Hardware cisco firepower_appliance_7010 - No
Hardware cisco firepower_appliance_7020 - No
Hardware cisco firepower_appliance_7030 - No
Hardware cisco firepower_appliance_7050 - No
Hardware cisco firepower_appliance_7110 - No
Hardware cisco firepower_appliance_7115 - No
Hardware cisco firepower_appliance_7120 - No
Hardware cisco firepower_appliance_7125 - No
Hardware cisco firepower_appliance_8120 - No
Hardware cisco firepower_appliance_8130 - No
Hardware cisco firepower_appliance_8140 - No
Hardware cisco firepower_appliance_8250 - No
Hardware cisco firepower_appliance_8260 - No
Hardware cisco firepower_appliance_8270 - No
Hardware cisco firepower_appliance_8290 - No
Hardware cisco firepower_appliance_8350 - No
Hardware cisco firepower_appliance_8360 - No
Hardware cisco firepower_appliance_8370 - No
Hardware cisco firepower_appliance_8390 - No
Hardware cisco firepower_management_center_1000 - No
Hardware cisco firepower_management_center_2000 - No
Hardware cisco firepower_management_center_2500 - No
Hardware cisco firepower_management_center_4000 - No
Hardware cisco firepower_management_center_4500 - No
Hardware cisco firesight_management_center_1500 - No
Hardware cisco firesight_management_center_3500 - No
Hardware cisco firesight_management_center_750 - No
Hardware cisco ngips_virtual_appliance - No

References