CVE-2018-0283 — Cleartext Transmission of Sensitive Info in Cisco Secure Firewall Management Center
Severity
5.8MEDIUMNVD
EPSS
0.4%
top 37.19%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedMay 2
Latest updateMay 13
Description
A vulnerability in the detection engine of Cisco Firepower System Software could allow an unauthenticated, remote attacker to restart an instance of the Snort detection engine on an affected device, resulting in a brief denial of service (DoS) condition. The vulnerability is due to the incorrect handling of Transport Layer Security (TLS) TCP connection setup for the affected software. An attacker could exploit this vulnerability by sending crafted TLS traffic to an affected device. A successful …
CVSS vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:LExploitability: 3.9 | Impact: 1.4
Affected Packages1 packages
🔴Vulnerability Details
2GHSA▶
GHSA-mgq6-c2x6-44g8: A vulnerability in the detection engine of Cisco Firepower System Software could allow an unauthenticated, remote attacker to restart an instance of t↗2022-05-13
CVEList▶
CVE-2018-0283: A vulnerability in the detection engine of Cisco Firepower System Software could allow an unauthenticated, remote attacker to restart an instance of t↗2018-05-02
📋Vendor Advisories
1Cisco
▶