CVE-2018-0237
published 2018-04-19CVE-2018-0237: A vulnerability in the file type detection mechanism of the Cisco Advanced Malware Protection (AMP) for Endpoints macOS Connector could allow an…
PriorityP432medium5.8CVSS 3.1
AVNACLPRNUINSCCNILAN
EPSS
1.22%
65.3th percentile
A vulnerability in the file type detection mechanism of the Cisco Advanced Malware Protection (AMP) for Endpoints macOS Connector could allow an unauthenticated, remote attacker to bypass malware detection. The vulnerability occurs because the software relies on only the file extension for detecting DMG files. An attacker could exploit this vulnerability by sending a DMG file with a nonstandard extension to a device that is running an affected AMP for Endpoints macOS Connector. An exploit could allow the attacker to bypass configured malware detection. Cisco Bug IDs: CSCve34034.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | advanced_malware_protection_for_endpoints | — | — |
| cisco | amp_for_endpoints_macos_connector_dmg_file_malware | — | — |
CVSS provenance
nvdv3.15.8MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:L/A:N
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:P/A:N
vendor_cisco5.8MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Cisco
Cisco AMP for Endpoints macOS Connector DMG File Malware Bypass Vulnerability
vendor_cisco·2018-04-18·CVSS 5.8
CVE-2018-0237 [MEDIUM] CWE-20 Cisco AMP for Endpoints macOS Connector DMG File Malware Bypass Vulnerability
Cisco AMP for Endpoints macOS Connector DMG File Malware Bypass Vulnerability
A vulnerability in the file type detection mechanism of the Cisco Advanced Malware Protection (AMP) for Endpoints macOS Connector could allow an unauthenticated, remote attacker to bypass malware detection.
The vulnerability occurs because the software relies on only the file extension for detecting DMG files. An attacker could exploit this vulnerability by sending a DMG file with a nonstandard extension to a device that is running an affected AMP for Endpoints macOS Connector. An exploit could allow the attacker to bypass configured malware detection.
There are no workarounds that address this vulnerability.
This advisory is available at the following link:
https://sec.cloudapps.cisco.com/security/center/con
Cisco
Cisco AMP for Endpoints macOS Connector DMG File Malware Bypass Vulnerability
vendor_cisco·CVSS 3.0
CVE-2018-0237 Cisco AMP for Endpoints macOS Connector DMG File Malware Bypass Vulnerability
CVE-2018-0237: Cisco AMP for Endpoints macOS Connector DMG File Malware Bypass Vulnerability
A vulnerability in the file type detection mechanism of the Cisco Advanced Malware Protection (AMP) for Endpoints macOS Connector could allow an unauthenticated, remote attacker to bypass malware detection. The vulnerability occurs because the software relies on only the file extension for detecting DMG files. An attacker could exploit this vulnerability by sending a DMG file with a nonstandard extension to a device that is running an affected AMP for Endpoints macOS Connector. An exploit could allow the attacker to bypass configured malware detection. There are no
CVSS: 3.0
CWE: CWE-20, CWE-20
Bug IDs: CSCve34034
GHSA
GHSA-c2m9-xh9p-789c: A vulnerability in the file type detection mechanism of the Cisco Advanced Malware Protection (AMP) for Endpoints macOS Connector could allow an unaut
ghsa_unreviewed·2022-05-13
CVE-2018-0237 [MEDIUM] CWE-706 GHSA-c2m9-xh9p-789c: A vulnerability in the file type detection mechanism of the Cisco Advanced Malware Protection (AMP) for Endpoints macOS Connector could allow an unaut
A vulnerability in the file type detection mechanism of the Cisco Advanced Malware Protection (AMP) for Endpoints macOS Connector could allow an unauthenticated, remote attacker to bypass malware detection. The vulnerability occurs because the software relies on only the file extension for detecting DMG files. An attacker could exploit this vulnerability by sending a DMG file with a nonstandard extension to a device that is running an affected AMP for Endpoints macOS Connector. An exploit could allow the attacker to bypass configured malware detection. Cisco Bug IDs: CSCve34034.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20180418-amphttps://wwws.nightwatchcybersecurity.com/2018/02/25/research-compressed-files-auto-detection-on-macos/https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20180418-amphttps://wwws.nightwatchcybersecurity.com/2018/02/25/research-compressed-files-auto-detection-on-macos/
2018-04-19
Published