CVE-2019-1951
published 2019-08-08CVE-2019-1951: A vulnerability in the packet filtering features of Cisco SD-WAN Solution could allow an unauthenticated, remote attacker to bypass L3 and L4 traffic filters…
PriorityP336medium5.8CVSS 3.1
AVNACLPRNUINSCCNILAN
EPSS
1.46%
70.7th percentile
A vulnerability in the packet filtering features of Cisco SD-WAN Solution could allow an unauthenticated, remote attacker to bypass L3 and L4 traffic filters. The vulnerability is due to improper traffic filtering conditions on an affected device. An attacker could exploit this vulnerability by crafting a malicious TCP packet with specific characteristics and sending it to a target device. A successful exploit could allow the attacker to bypass the L3 and L4 traffic filters and inject an arbitrary packet in the network.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | cisco_sd-wan_solution | >= unspecified < 19.1.0 | 19.1.0 |
| cisco | sd-wan_firmware | <= 19.1.0 | — |
| cisco | sd-wan_solution_packet_filtering | — | — |
CVSS provenance
nvdv3.15.8MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:L/A:N
nvdv3.05.8MEDIUMCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:L/A:N
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:P/A:N
vendor_cisco5.8MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-xpmg-vx7g-292w: A vulnerability in the packet filtering features of Cisco SD-WAN Solution could allow an unauthenticated, remote attacker to bypass L3 and L4 traffic
ghsa_unreviewed·2022-05-24
CVE-2019-1951 [MEDIUM] GHSA-xpmg-vx7g-292w: A vulnerability in the packet filtering features of Cisco SD-WAN Solution could allow an unauthenticated, remote attacker to bypass L3 and L4 traffic
A vulnerability in the packet filtering features of Cisco SD-WAN Solution could allow an unauthenticated, remote attacker to bypass L3 and L4 traffic filters. The vulnerability is due to improper traffic filtering conditions on an affected device. An attacker could exploit this vulnerability by crafting a malicious TCP packet with specific characteristics and sending it to a target device. A successful exploit could allow the attacker to bypass the L3 and L4 traffic filters and inject an arbitrary packet in the network.
Cisco
Cisco SD-WAN Solution Packet Filtering Bypass Vulnerability
vendor_cisco·2019-08-07·CVSS 5.8
CVE-2019-1951 [MEDIUM] CWE-20 Cisco SD-WAN Solution Packet Filtering Bypass Vulnerability
Cisco SD-WAN Solution Packet Filtering Bypass Vulnerability
A vulnerability in the packet filtering features of Cisco SD-WAN Solution could allow an unauthenticated, remote attacker to bypass L3 and L4 traffic filters.
The vulnerability is due to improper traffic filtering conditions on an affected device. An attacker could exploit this vulnerability by crafting a malicious TCP packet with specific characteristics and sending it to a target device. A successful exploit could allow the attacker to bypass the L3 and L4 traffic filters and inject an arbitrary packet in the network.
There are no workarounds that address this vulnerability.
This advisory is available at the following link:
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20190807-sd-wan-by
Cisco
Cisco SD-WAN Solution Packet Filtering Bypass Vulnerability
vendor_cisco·CVSS 3.0
CVE-2019-1951 Cisco SD-WAN Solution Packet Filtering Bypass Vulnerability
CVE-2019-1951: Cisco SD-WAN Solution Packet Filtering Bypass Vulnerability
A vulnerability in the packet filtering features of Cisco SD-WAN Solution could allow an unauthenticated, remote attacker to bypass L3 and L4 traffic filters. The vulnerability is due to improper traffic filtering conditions on an affected device. An attacker could exploit this vulnerability by crafting a malicious TCP packet with specific characteristics and sending it to a target device. A successful exploit could allow the attacker to bypass the L3 and L4 traffic filters and inject an arbitrary packet in the network. There are no
CVSS: 3.0
CWE: CWE-20, CWE-20
Bug IDs: CSCvn67202, CSCvr64177, CSCvr64177
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2019-11729 nss: Empty or malformed p256-ECDH public keys may trigger a segmentation fault
bugzilla·2019-07-10·CVSS 7.5
CVE-2019-11729 [HIGH] CVE-2019-11729 nss: Empty or malformed p256-ECDH public keys may trigger a segmentation fault
CVE-2019-11729 nss: Empty or malformed p256-ECDH public keys may trigger a segmentation fault
Empty or malformed p256-ECDH public keys may trigger a segmentation fault due values being improperly sanitized before being copied into memory and used.
External Reference:
https://www.mozilla.org/en-US/security/advisories/mfsa2019-22/#CVE-2019-11729
Discussion:
Acknowledgments:
Name: the Mozilla project
Upstream: Jonas Allmann
---
Statement:
Firefox on Red Hat Enterprise Linux is built against the system nss library.
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 8
Via RHSA-2019:1951 https://access.redhat.com/errata/RHSA-2019:1951
---
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s):
https
Bugzilla
CVE-2019-11719 nss: Out-of-bounds read when importing curve25519 private key
bugzilla·2019-07-10·CVSS 7.5
CVE-2019-11719 [HIGH] CVE-2019-11719 nss: Out-of-bounds read when importing curve25519 private key
CVE-2019-11719 nss: Out-of-bounds read when importing curve25519 private key
When importing a curve25519 private key in PKCS#8format with leading 0x00 bytes, it is possible to trigger an out-of-bounds read in the Network Security Services (NSS) library. This could lead to information disclosure.
External Reference:
https://www.mozilla.org/en-US/security/advisories/mfsa2019-22/#CVE-2019-11719
Discussion:
Acknowledgments:
Name: the Mozilla project
Upstream: Henry Corrigan-Gibbs
---
Statement:
Firefox on Red Hat Enterprise Linux is built against the system nss library.
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 8
Via RHSA-2019:1951 https://access.redhat.com/errata/RHSA-2019:1951
---
This bug is now closed. Further updates for individu
Bugzilla
CVE-2018-18508 nss: NULL pointer dereference in several CMS functions resulting in a denial of service
bugzilla·2019-01-31·CVSS 6.5
CVE-2018-18508 [MEDIUM] CVE-2018-18508 nss: NULL pointer dereference in several CMS functions resulting in a denial of service
CVE-2018-18508 nss: NULL pointer dereference in several CMS functions resulting in a denial of service
A NULL pointer dereference issue was found in several CMS function. A specially crafted data could possibly crash nss.
External References:
https://developer.mozilla.org/en-US/docs/Mozilla/Projects/NSS/NSS_3.41.1_release_notes
Discussion:
Created nss tracking bugs for this issue:
Affects: fedora-all [bug 1671311]
---
Upstream patch:
https://hg.mozilla.org/projects/nss/rev/08d1b0c1117f
https://hg.mozilla.org/projects/nss/rev/5e70b72131ac
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 8
Via RHSA-2019:1951 https://access.redhat.com/errata/RHSA-2019:1951
---
This bug is now closed. Further updates for individual products will be reflected
2019-08-08
Published