CVE-2019-12697Protection Mechanism Failure in Cisco Firesight System Software

Severity
7.5HIGHNVD
EPSS
0.3%
top 48.65%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedOct 2
Latest updateMay 24

Description

Multiple vulnerabilities in the Cisco Firepower System Software Detection Engine could allow an unauthenticated, remote attacker to bypass configured Malware and File Policies for RTF and RAR file types. For more information about these vulnerabilities, see the Details section of this advisory.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:NExploitability: 3.9 | Impact: 3.6

Affected Packages2 packages

CVEListV5cisco/cisco_firesight_system_softwareunspecifiedn/a
NVDcisco/firepower4 versions+3

🔴Vulnerability Details

2
GHSA
GHSA-rrfx-pqr3-w8hw: Multiple vulnerabilities in the Cisco Firepower System Software Detection Engine could allow an unauthenticated, remote attacker to bypass configured2022-05-24
CVEList
Cisco Firepower System Software Detection Engine RTF and RAR Malware and File Policy Bypass Vulnerabilities2019-10-02

📋Vendor Advisories

1
Cisco
Cisco Firepower System Software Detection Engine RTF and RAR Malware and File Policy Bypass Vulnerabilities2019-10-02
CVE-2019-12697 — Protection Mechanism Failure in Cisco | cvebase