Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2019-12697


Multiple vulnerabilities in the Cisco Firepower System Software Detection Engine could allow an unauthenticated, remote attacker to bypass configured Malware and File Policies for RTF and RAR file types. For more information about these vulnerabilities, see the Details section of this advisory.


Published

2019-10-02T19:15:13.593

Last Modified

2024-11-21T04:23:23.040

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 7.5 (HIGH)

CVSSv2 Vector

AV:N/AC:L/Au:N/C:N/I:P/A:N

  • Access Vector: NETWORK
  • Access Complexity: LOW
  • Authentication: NONE
  • Confidentiality Impact: NONE
  • Integrity Impact: PARTIAL
  • Availability Impact: NONE
Exploitability Score

10.0

Impact Score

2.9

Weaknesses
  • Type: Secondary
    CWE-693
  • Type: Primary
    NVD-CWE-Other

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application cisco firepower 6.2.3.1 Yes
Application cisco firepower 6.2.3.7 Yes
Application cisco firepower 6.3.0 Yes
Application cisco firepower 6.4.0 Yes
Hardware cisco asa_5500-x - No
Hardware cisco firepower_1010 - No
Hardware cisco firepower_1120 - No
Hardware cisco firepower_1140 - No
Hardware cisco firepower_2110 - No
Hardware cisco firepower_2120 - No
Hardware cisco firepower_2130 - No
Hardware cisco firepower_2140 - No
Hardware cisco firepower_4110 - No
Hardware cisco firepower_4115 - No
Hardware cisco firepower_4120 - No
Hardware cisco firepower_4125 - No
Hardware cisco firepower_4140 - No
Hardware cisco firepower_4145 - No
Hardware cisco firepower_4150 - No
Hardware cisco firepower_7000 - No
Hardware cisco firepower_8000 - No
Hardware cisco firepower_9300 - No
Hardware cisco firepower_threat_defense_for_isr - No
Hardware cisco ftd_virtual - No
Hardware cisco isa_3000 - No
Hardware cisco ngipsv_for_vmware - No

References