SB2018051718 - Security restrictions bypass in Cisco Firepower Management



SB2018051718 - Security restrictions bypass in Cisco Firepower Management

Published: May 17, 2018

Security Bulletin ID SB2018051718
Severity
Low
Patch available
YES
Number of vulnerabilities 1
Exploitation vector Remote access
Highest impact Data manipulation

Breakdown by Severity

Low 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 security vulnerability.


1) Data handling (CVE-ID: CVE-2018-0297)

The vulnerability allows a remote unauthenticated attacker to bypass security restrictions and write arbitrary files on the target system.

The weakness exists in the detection engine due to the incorrect handling of TCP SSL packets received out of order. A remote attacker can send a specially crafted SSL connection, bypass a configured SSL AC policy and block SSL traffic.

Remediation

Install update from vendor's website.