CVE-2018-0333
published 2018-06-07CVE-2018-0333: A vulnerability in the VPN configuration management of Cisco FireSIGHT System Software could allow an unauthenticated, remote attacker to bypass VPN security…
PriorityP434medium5.8CVSS 3.0
AVNACLPRNUINSCCLINAN
EPSS
1.92%
77.6th percentile
A vulnerability in the VPN configuration management of Cisco FireSIGHT System Software could allow an unauthenticated, remote attacker to bypass VPN security due to unintended side effects of dynamic configuration changes that could allow an attacker to bypass configured policies. The vulnerability is due to incorrect management of the configured interface names and VPN parameters when dynamic CLI configuration changes are performed. An attacker could exploit this vulnerability by sending packets through an interface on the targeted device. A successful exploit could allow the attacker to bypass configured VPN policies. Cisco Bug IDs: CSCvh49388.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | firesight_system_vpn_policy | — | — |
| cisco | secure_firewall_management_center | — | — |
CVSS provenance
nvdv3.05.8MEDIUMCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:N/A:N
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
vendor_cisco5.8MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Cisco
Cisco FireSIGHT System VPN Policy Bypass Vulnerability
vendor_cisco·2018-06-06·CVSS 5.8
CVE-2018-0333 [MEDIUM] CWE-693 Cisco FireSIGHT System VPN Policy Bypass Vulnerability
Cisco FireSIGHT System VPN Policy Bypass Vulnerability
A vulnerability in the VPN configuration management of Cisco FireSIGHT System Software could allow an unauthenticated,
remote attacker to bypass VPN security due to unintended side effects of dynamic configuration changes that could allow an attacker to bypass
configured policies.
The vulnerability is due to incorrect management of the configured interface names and VPN parameters when dynamic CLI configuration changes are
performed. An attacker could exploit this vulnerability by sending packets through an interface on the targeted device. A successful exploit could allow
the attacker to bypass configured VPN policies.
There are no workarounds that address this vulnerability.
This advisory is available at the following link:
https:/
Cisco
Cisco FireSIGHT System VPN Policy Bypass Vulnerability
vendor_cisco·CVSS 3.0
CVE-2018-0333 Cisco FireSIGHT System VPN Policy Bypass Vulnerability
CVE-2018-0333: Cisco FireSIGHT System VPN Policy Bypass Vulnerability
A vulnerability in the VPN configuration management of Cisco FireSIGHT System Software could allow an unauthenticated, remote attacker to bypass VPN security due to unintended side effects of dynamic configuration changes that could allow an attacker to bypass configured policies. The vulnerability is due to incorrect management of the configured interface names and VPN parameters when dynamic CLI configuration changes are performed. An attacker could exploit this vulnerability by sending packets through an interface on the targeted device. A successful exploit could allow the attacker to bypass configured VPN policies. There are no
CVSS: 3.0
CWE: CWE-693, CWE-693
Bug IDs: CSCvh49388
GHSA
GHSA-3mhr-frr8-qmc6: A vulnerability in the VPN configuration management of Cisco FireSIGHT System Software could allow an unauthenticated, remote attacker to bypass VPN s
ghsa_unreviewed·2022-05-13
CVE-2018-0333 [MEDIUM] CWE-693 GHSA-3mhr-frr8-qmc6: A vulnerability in the VPN configuration management of Cisco FireSIGHT System Software could allow an unauthenticated, remote attacker to bypass VPN s
A vulnerability in the VPN configuration management of Cisco FireSIGHT System Software could allow an unauthenticated, remote attacker to bypass VPN security due to unintended side effects of dynamic configuration changes that could allow an attacker to bypass configured policies. The vulnerability is due to incorrect management of the configured interface names and VPN parameters when dynamic CLI configuration changes are performed. An attacker could exploit this vulnerability by sending packets through an interface on the targeted device. A successful exploit could allow the attacker to bypass configured VPN policies. Cisco Bug IDs: CSCvh49388.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2018-06-07
Published