Security restrictions bypass in Cisco Web Security Appliance - CVE-2018-0353
Published: June 6, 2018 / Updated: June 7, 2018
Cisco Web Security Appliance
Detailed vulnerability description
The vulnerability allows a remote attacker to bypass security restrictions on the target system.
The vulnerability exists in traffic-monitoring functions in Cisco Web Security Appliance (WSA) due to a change in the underlying operating system software that is responsible for monitoring affected traffic. A remote unauthenticated attacker can send a specially crafted IP packets, circumvent Layer 4 Traffic Monitor (L4TM) functionality, pass traffic through the device, which the WSA was configured to deny.