#VU12792 Data handling in Cisco Secure Firewall Management Center (formerly Firepower Management Center, FMC) - CVE-2018-0297
Published: May 17, 2018 / Updated: May 17, 2018
Vulnerability identifier: #VU12792
Vulnerability risk: Low
CVSSv4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:U/U:Clear
CVE-ID: CVE-2018-0297
CWE-ID: CWE-19
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerable software:
Cisco Secure Firewall Management Center (formerly Firepower Management Center, FMC)
Cisco Secure Firewall Management Center (formerly Firepower Management Center, FMC)
Software vendor:
Cisco Systems, Inc
Cisco Systems, Inc
Description
The vulnerability allows a remote unauthenticated attacker to bypass security restrictions and write arbitrary files on the target system.
The weakness exists in the detection engine due to the incorrect handling of TCP SSL packets received out of order. A remote attacker can send a specially crafted SSL connection, bypass a configured SSL AC policy and block SSL traffic.
The weakness exists in the detection engine due to the incorrect handling of TCP SSL packets received out of order. A remote attacker can send a specially crafted SSL connection, bypass a configured SSL AC policy and block SSL traffic.
Remediation
Update to version 6.2.3 or 6.2.2.3.