SB2019020708 - Security restrictions bypass in Cisco Web Security Appliance
Published: February 7, 2019
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Security restrictions bypass (CVE-ID: CVE-2019-1672)
The vulnerability allows a remote attacker to bypass security restrictions on the system.
The vulnerability exists in the Decryption Policy Default Action functionality due to the incorrect handling of SSL-encrypted traffic when Decrypt for End-User Notification is disabled in the configuration. A remote attacker can send a SSL connection through the affected device to bypass a configured drop policy to block specific SSL connections and allow traffic onto the network that should have been denied.
Remediation
Install update from vendor's website.