Security restrictions bypass in Cisco Firepower Management Center

Published: 2018-11-08 11:24:31
Severity Low
Patch available YES
Number of vulnerabilities 1
CVE ID CVE-2018-15443
CVSSv3 5.1 [CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:L/A:N/E:U/RL:O/RC:C]
CWE ID CWE-119
Exploitation vector Network
Public exploit Not available
Vulnerable software Cisco Firepower Management Center
Vulnerable software versions Cisco Firepower Management Center 6.1.0.6
Cisco Firepower Management Center 6.2.3.3
Cisco Firepower Management Center 6.2.0.6
Cisco Firepower Management Center 6.2.2.4
Vendor URL Cisco Systems, Inc

Security Advisory

1) Security restrictions bypass

Description

The vulnerability allows a remote attacker to bypass security restrictions on the target system.

The vulnerability exists in the detection engine due to incorrect TCP retransmission handling. A remote unauthenticated attacker can send a specially crafted TCP connection request through an affected device and bypass configured Intrusion Prevention System (IPS) rules and allow uninspected traffic onto the network.

Remediation

Update to version 6.2.3.6.

External links

https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20181107-fde-tcp-bypa...

Back to List