#VU12792 Data handling in Cisco Secure Firewall Management Center (formerly Firepower Management Center, FMC) - CVE-2018-0297

 

#VU12792 Data handling in Cisco Secure Firewall Management Center (formerly Firepower Management Center, FMC) - CVE-2018-0297

Published: May 17, 2018 / Updated: May 17, 2018


Vulnerability identifier: #VU12792
Vulnerability risk: Low
CVSSv4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:U/U:Clear
CVE-ID: CVE-2018-0297
CWE-ID: CWE-19
Exploitation vector: Remote access
Exploit availability: No public exploit available
Vulnerable software:
Cisco Secure Firewall Management Center (formerly Firepower Management Center, FMC)
Software vendor:
Cisco Systems, Inc

Description

The vulnerability allows a remote unauthenticated attacker to bypass security restrictions and write arbitrary files on the target system.

The weakness exists in the detection engine due to the incorrect handling of TCP SSL packets received out of order. A remote attacker can send a specially crafted SSL connection, bypass a configured SSL AC policy and block SSL traffic.

Remediation

Update to version 6.2.3 or 6.2.2.3.

External links