CVE-2018-0254
published 2018-04-19CVE-2018-0254: A vulnerability in the detection engine of Cisco Firepower System Software could allow an unauthenticated, remote attacker to bypass configured file action…
PriorityP432medium5.3CVSS 3.0
AVNACLPRNUINSUCNILAN
EPSS
1.23%
65.8th percentile
A vulnerability in the detection engine of Cisco Firepower System Software could allow an unauthenticated, remote attacker to bypass configured file action policies if an Intelligent Application Bypass (IAB) with a drop percentage threshold is also configured. The vulnerability is due to incorrect counting of the percentage of dropped traffic. An attacker could exploit this vulnerability by sending network traffic to a targeted device. An exploit could allow the attacker to bypass configured file action policies, and traffic that should be dropped could be allowed into the network. Cisco Bug IDs: CSCvf86435.
Affected
5 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | firepower_system | — | — |
| cisco | firepower_threat_defense | — | — |
| cisco | firepower_threat_defense | — | — |
| cisco | firepower_threat_defense | — | — |
| cisco | firepower_threat_defense | — | — |
CVSS provenance
nvdv3.05.3MEDIUMCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:P/A:N
vendor_cisco5.8MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Cisco
Cisco Firepower System Software Intelligent Application Bypass Vulnerability
vendor_cisco·2018-04-18·CVSS 5.8
CVE-2018-0254 [MEDIUM] CWE-693 Cisco Firepower System Software Intelligent Application Bypass Vulnerability
Cisco Firepower System Software Intelligent Application Bypass Vulnerability
A vulnerability in the detection engine of Cisco Firepower System Software could allow an unauthenticated, remote attacker to bypass configured file action policies if an Intelligent Application Bypass (IAB) with a drop percentage threshold is also configured.
The vulnerability is due to incorrect counting of the percentage of dropped traffic. An attacker could exploit this vulnerability by sending network traffic to a targeted device. An exploit could allow the attacker to bypass configured file action policies, and traffic that should be dropped could be allowed into the network.
There are no workarounds that address this vulnerability.
This advisory is available at the following link:
https://sec.cloudapps.
Cisco
Cisco Firepower System Software Intelligent Application Bypass Vulnerability
vendor_cisco·CVSS 3.0
CVE-2018-0254 Cisco Firepower System Software Intelligent Application Bypass Vulnerability
CVE-2018-0254: Cisco Firepower System Software Intelligent Application Bypass Vulnerability
A vulnerability in the detection engine of Cisco Firepower System Software could allow an unauthenticated, remote attacker to bypass configured file action policies if an Intelligent Application Bypass (IAB) with a drop percentage threshold is also configured. The vulnerability is due to incorrect counting of the percentage of dropped traffic. An attacker could exploit this vulnerability by sending network traffic to a targeted device. An exploit could allow the attacker to bypass configured file action policies, and traffic that should be dropped could be allowed into the network. There are no
CVSS: 3.0
CWE: CWE-693, CWE-693
Bug IDs: CSCvf86435
GHSA
GHSA-h2c2-gxr2-8xp4: A vulnerability in the detection engine of Cisco Firepower System Software could allow an unauthenticated, remote attacker to bypass configured file a
ghsa_unreviewed·2022-05-13
CVE-2018-0254 [MEDIUM] CWE-693 GHSA-h2c2-gxr2-8xp4: A vulnerability in the detection engine of Cisco Firepower System Software could allow an unauthenticated, remote attacker to bypass configured file a
A vulnerability in the detection engine of Cisco Firepower System Software could allow an unauthenticated, remote attacker to bypass configured file action policies if an Intelligent Application Bypass (IAB) with a drop percentage threshold is also configured. The vulnerability is due to incorrect counting of the percentage of dropped traffic. An attacker could exploit this vulnerability by sending network traffic to a targeted device. An exploit could allow the attacker to bypass configured file action policies, and traffic that should be dropped could be allowed into the network. Cisco Bug IDs: CSCvf86435.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2018-04-19
Published