CVE-2018-0254
טרם דורגה
תיאור (מקור, אנגלית)
A vulnerability in the detection engine of Cisco Firepower System Software could allow an unauthenticated, remote attacker to bypass configured file action policies if an Intelligent Application Bypass (IAB) with a drop percentage threshold is also configured. The vulnerability is due to incorrect counting of the percentage of dropped traffic. An attacker could exploit this vulnerability by sending network traffic to a targeted device. An exploit could allow the attacker to bypass configured file action policies, and traffic that should be dropped could be allowed into the network. Cisco Bug IDs: CSCvf86435.
מדדים
- EPSS — סבירות ניצול
- 1% (אחוזון 100) נכון ל-15/8/2026
- CWE
- CWE-693
מוצרים מושפעים
cisco: secure firewall threat defense; cisco: amp 7150; cisco: amp 8150; cisco: firepower appliance 7010; cisco: firepower appliance 7020; cisco: firepower appliance 7030; cisco: firepower appliance 7050; cisco: firepower appliance 7110; cisco: firepower appliance 7115; cisco: firepower appliance 7120; cisco: firepower appliance 7125; cisco: firepower appliance 8120; cisco: firepower appliance 8130; cisco: firepower appliance 8140; cisco: firepower appliance 8250
קישורים
- https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa… Vendor Advisory
- https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa… Vendor Advisory
- http://www.securityfocus.com/bid/103940 Third Party AdvisoryVDB Entry
- http://www.securityfocus.com/bid/103940 Third Party AdvisoryVDB Entry