CVE-2018-0297
published 2018-05-17CVE-2018-0297: A vulnerability in the detection engine of Cisco Firepower Threat Defense software could allow an unauthenticated, remote attacker to bypass a configured…
PriorityP432medium5.8CVSS 3.0
AVNACLPRNUINSCCNILAN
EPSS
1.23%
65.8th percentile
A vulnerability in the detection engine of Cisco Firepower Threat Defense software could allow an unauthenticated, remote attacker to bypass a configured Secure Sockets Layer (SSL) Access Control (AC) policy to block SSL traffic. The vulnerability is due to the incorrect handling of TCP SSL packets received out of order. An attacker could exploit this vulnerability by sending a crafted SSL connection through the affected device. A successful exploit could allow the attacker to bypass a configured SSL AC policy to block SSL traffic. Cisco Bug IDs: CSCvg09316.
Affected
5 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | firepower_threat_defense | — | — |
| cisco | firepower_threat_defense | — | — |
| cisco | firepower_threat_defense | — | — |
| cisco | firepower_threat_defense | — | — |
| cisco | firepower_threat_defense | — | — |
CVSS provenance
nvdv3.05.8MEDIUMCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:L/A:N
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:P/A:N
vendor_cisco5.8MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-9j44-j9v3-4928: A vulnerability in the detection engine of Cisco Firepower Threat Defense software could allow an unauthenticated, remote attacker to bypass a configu
ghsa_unreviewed·2022-05-13
CVE-2018-0297 [MEDIUM] CWE-693 GHSA-9j44-j9v3-4928: A vulnerability in the detection engine of Cisco Firepower Threat Defense software could allow an unauthenticated, remote attacker to bypass a configu
A vulnerability in the detection engine of Cisco Firepower Threat Defense software could allow an unauthenticated, remote attacker to bypass a configured Secure Sockets Layer (SSL) Access Control (AC) policy to block SSL traffic. The vulnerability is due to the incorrect handling of TCP SSL packets received out of order. An attacker could exploit this vulnerability by sending a crafted SSL connection through the affected device. A successful exploit could allow the attacker to bypass a configured SSL AC policy to block SSL traffic. Cisco Bug IDs: CSCvg09316.
Cisco
Cisco Firepower Threat Defense Software Policy Bypass Vulnerability
vendor_cisco·2018-05-16·CVSS 5.8
CVE-2018-0297 [MEDIUM] CWE-693 Cisco Firepower Threat Defense Software Policy Bypass Vulnerability
Cisco Firepower Threat Defense Software Policy Bypass Vulnerability
A vulnerability in the detection engine of Cisco Firepower Threat Defense software could allow an unauthenticated, remote attacker to bypass a configured Secure Sockets Layer (SSL) Access Control (AC) policy to block SSL traffic.
The vulnerability is due to the incorrect handling of TCP SSL packets received out of order. An attacker could exploit this vulnerability by sending a crafted SSL connection through the affected device. A successful exploit could allow the attacker to bypass a configured SSL AC policy to block SSL traffic.
There are no workarounds that address this vulnerability.
This advisory is available at the following link:
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco
Cisco
Cisco Firepower Threat Defense Software Policy Bypass Vulnerability
vendor_cisco·CVSS 3.0
CVE-2018-0297 Cisco Firepower Threat Defense Software Policy Bypass Vulnerability
CVE-2018-0297: Cisco Firepower Threat Defense Software Policy Bypass Vulnerability
A vulnerability in the detection engine of Cisco Firepower Threat Defense software could allow an unauthenticated, remote attacker to bypass a configured Secure Sockets Layer (SSL) Access Control (AC) policy to block SSL traffic. The vulnerability is due to the incorrect handling of TCP SSL packets received out of order. An attacker could exploit this vulnerability by sending a crafted SSL connection through the affected device. A successful exploit could allow the attacker to bypass a configured SSL AC policy to block SSL traffic. There are no
CVSS: 3.0
CWE: CWE-693, CWE-693
Bug IDs: CSCvg09316
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2018-05-17
Published