Resource exhaustion in Cisco Secure Firewall Management Center (formerly Firepower Management Center, FMC) - CVE-2018-0272

 

Resource exhaustion in Cisco Secure Firewall Management Center (formerly Firepower Management Center, FMC) - CVE-2018-0272

Published: April 23, 2018


Vulnerability identifier: #VU12083
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2018-0272
CWE-ID: CWE-400
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote unauthenticated attacker to cause DoS condition on the target system.

The weakness exists due to improper error handling while processing SSL traffic. A remote attacker can send a large volume of specially crafted SSL traffic, trigger a persistent high CPU utilization condition, degrade the device performance and cause the service to crash.

Affected software

Cisco Secure Firewall Management Center (formerly Firepower Management Center, FMC)

How to mitigate CVE-2018-0272

Update to version 6.2.3.


External References

Related Security Bulletins