CVE-2017-12303
published 2017-11-16CVE-2017-12303: A vulnerability in the Advanced Malware Protection (AMP) file filtering feature of Cisco AsyncOS Software for Cisco Web Security Appliance (WSA) could allow an…
PriorityP432medium5.3CVSS 3.0
AVNACLPRNUINSUCNILAN
EPSS
1.64%
73.7th percentile
A vulnerability in the Advanced Malware Protection (AMP) file filtering feature of Cisco AsyncOS Software for Cisco Web Security Appliance (WSA) could allow an unauthenticated, remote attacker to bypass a configured AMP file filtering rule. The file types affected are zipped or archived file types. The vulnerability is due to incorrect and different file hash values when AMP scans the file. An attacker could exploit this vulnerability by sending a crafted email file attachment through the targeted device. An exploit could allow the attacker to bypass a configured AMP file filter. Cisco Bug IDs: CSCvf52943.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | asyncos | — | — |
| cisco | asyncos | — | — |
| cisco | web_security_appliance_advanced_malware_protection_file | — | — |
CVSS provenance
nvdv3.05.3MEDIUMCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:P/A:N
vendor_cisco5.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Cisco
Cisco Web Security Appliance Advanced Malware Protection File Bypass Vulnerability
vendor_cisco·2017-11-15·CVSS 5.3
CVE-2017-12303 [MEDIUM] CWE-358 Cisco Web Security Appliance Advanced Malware Protection File Bypass Vulnerability
Cisco Web Security Appliance Advanced Malware Protection File Bypass Vulnerability
A vulnerability in the Advanced Malware Protection (AMP) file filtering feature of Cisco AsyncOS Software for Cisco Web Security Appliance (WSA) could allow an unauthenticated, remote attacker to bypass a configured AMP file filtering rule. The file types affected are zipped or archived file types.
The vulnerability is due to incorrect and different file hash values when AMP scans the file. An attacker could exploit this vulnerability by sending a crafted email file attachment through the targeted device. An exploit could allow the attacker to bypass a configured AMP file filter.
There are no workarounds that address this vulnerability.
This advisory is available at the following link:
https://sec.clouda
Cisco
Cisco Web Security Appliance Advanced Malware Protection File Bypass Vulnerability
vendor_cisco·CVSS 3.0
CVE-2017-12303 Cisco Web Security Appliance Advanced Malware Protection File Bypass Vulnerability
CVE-2017-12303: Cisco Web Security Appliance Advanced Malware Protection File Bypass Vulnerability
A vulnerability in the Advanced Malware Protection (AMP) file filtering feature of Cisco AsyncOS Software for Cisco Web Security Appliance (WSA) could allow an unauthenticated, remote attacker to bypass a configured AMP file filtering rule. The file types affected are zipped or archived file types. The vulnerability is due to incorrect and different file hash values when AMP scans the file. An attacker could exploit this vulnerability by sending a crafted email file attachment through the targeted device. An exploit could allow the attacker to bypass a configured AMP file filter. There are no
CVSS: 3.0
CWE: CWE-358, CWE-358
Bug IDs: CSCvf52943
GHSA
GHSA-3hr9-5q4c-rq22: A vulnerability in the Advanced Malware Protection (AMP) file filtering feature of Cisco AsyncOS Software for Cisco Web Security Appliance (WSA) could
ghsa_unreviewed·2022-05-13
CVE-2017-12303 [MEDIUM] CWE-358 GHSA-3hr9-5q4c-rq22: A vulnerability in the Advanced Malware Protection (AMP) file filtering feature of Cisco AsyncOS Software for Cisco Web Security Appliance (WSA) could
A vulnerability in the Advanced Malware Protection (AMP) file filtering feature of Cisco AsyncOS Software for Cisco Web Security Appliance (WSA) could allow an unauthenticated, remote attacker to bypass a configured AMP file filtering rule. The file types affected are zipped or archived file types. The vulnerability is due to incorrect and different file hash values when AMP scans the file. An attacker could exploit this vulnerability by sending a crafted email file attachment through the targeted device. An exploit could allow the attacker to bypass a configured AMP file filter. Cisco Bug IDs: CSCvf52943.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://www.securityfocus.com/bid/101932http://www.securitytracker.com/id/1039828https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20171115-wsahttp://www.securityfocus.com/bid/101932http://www.securitytracker.com/id/1039828https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20171115-wsa
2017-11-16
Published