Resource exhaustion in Cisco Secure Firewall Management Center (formerly Firepower Management Center, FMC) - CVE-2018-0233

 

Resource exhaustion in Cisco Secure Firewall Management Center (formerly Firepower Management Center, FMC) - CVE-2018-0233

Published: April 23, 2018


Vulnerability identifier: #VU12081
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2018-0233
CWE-ID: CWE-400
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote unauthenticated attacker to cause DoS condition on the target system.

The weakness exists in the Secure Sockets Layer (SSL) packet reassembly functionality of the detection engine due to improper handling of changes to SSL connection states. A remote attacker can send specially crafted SSL connections, trigger the detection engine to consume excessive system memory and cause the service to crash.

Affected software

Cisco Secure Firewall Management Center (formerly Firepower Management Center, FMC)

How to mitigate CVE-2018-0233

Update to versions 6.2.1, 6.2.0.3 or 6.1.0.6.


External References

Related Security Bulletins