Data handling in Cisco Secure Firewall Management Center (formerly Firepower Management Center, FMC) - CVE-2018-0297

 

Data handling in Cisco Secure Firewall Management Center (formerly Firepower Management Center, FMC) - CVE-2018-0297

Published: May 17, 2018 / Updated: May 17, 2018


Vulnerability identifier: #VU12792
CSH Severity: Low
CVSS v4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:U/U:Clear
CVE-ID: CVE-2018-0297
CWE-ID: CWE-19
Exploitation vector: Remote access
Exploit availability: No public exploit available
Vendor: Cisco Systems, Inc
Affected software:
Cisco Secure Firewall Management Center (formerly Firepower Management Center, FMC)

Detailed vulnerability description

The vulnerability allows a remote unauthenticated attacker to bypass security restrictions and write arbitrary files on the target system.

The weakness exists in the detection engine due to the incorrect handling of TCP SSL packets received out of order. A remote attacker can send a specially crafted SSL connection, bypass a configured SSL AC policy and block SSL traffic.

How to mitigate CVE-2018-0297

Update to version 6.2.3 or 6.2.2.3.

Sources