Improper input validation in Cisco Immunet - CVE-2018-15437

 

Improper input validation in Cisco Immunet - CVE-2018-15437

Published: November 7, 2018 / Updated: June 17, 2021


Vulnerability identifier: #VU15774
CSH Severity: Low
CVSS v4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2018-15437
CWE-ID: CWE-20
Exploitation vector: Local access
Exploit availability: Public exploit is available

Vulnerability details

The vulnerability allows a local attacker to cause DoS condition on the target system.

The vulnerability exists in the system scanning component due to improper process resource handling. A local attacker on a system running Microsoft Windows, execute a malicious file to prevent the scanning services from functioning properly and ultimately prevent the system from being protected from further intrusion.


Affected software

Cisco Immunet
Cisco AMP for Endpoints

How to mitigate CVE-2018-15437

Update to version 6.2.0.

Cisco Immunet - update to 6.2.0
Cisco AMP for Endpoints - update to 6.2.1

Links to Public Exploits and PoC-codes

External References

Related Security Bulletins