CVE-2018-0370Cisco Secure Firewall Management Center vulnerability

CWE-3994 documents4 sources
Severity
7.5HIGHNVD
EPSS
1.1%
top 21.84%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJul 16
Latest updateMay 13

Description

A vulnerability in the detection engine of Cisco Firepower System Software could allow an unauthenticated, remote attacker to cause one of the detection engine processes to run out of memory and thus slow down traffic processing. The vulnerability is due to improper handling of traffic when the Secure Sockets Layer (SSL) inspection policy is enabled. An attacker could exploit this vulnerability by sending malicious traffic through an affected device. An exploit could allow the attacker to increa

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:HExploitability: 3.9 | Impact: 3.6

Affected Packages1 packages

NVDcisco/secure_firewall_management_center6.1.0.7, 6.2.0.5, 6.2.2.2+2

🔴Vulnerability Details

2
GHSA
GHSA-j95f-5r5g-7mrr: A vulnerability in the detection engine of Cisco Firepower System Software could allow an unauthenticated, remote attacker to cause one of the detecti2022-05-13
CVEList
CVE-2018-0370: A vulnerability in the detection engine of Cisco Firepower System Software could allow an unauthenticated, remote attacker to cause one of the detecti2018-07-16

📋Vendor Advisories

1
Cisco
Cisco Firepower System Software Detection Engine Denial of Service Vulnerability2018-07-11
CVE-2018-0370 — Cisco vulnerability | cvebase