5
CVSSv2

CVE-2018-0254

Published: 19/04/2018 Updated: 09/10/2019
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
CVSS v3 Base Score: 5.3 | Impact Score: 1.4 | Exploitability Score: 3.9
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:N/I:P/A:N

Vulnerability Summary

A vulnerability in the detection engine of Cisco Firepower System Software could allow an unauthenticated, remote malicious user to bypass configured file action policies if an Intelligent Application Bypass (IAB) with a drop percentage threshold is also configured. The vulnerability is due to incorrect counting of the percentage of dropped traffic. An attacker could exploit this vulnerability by sending network traffic to a targeted device. An exploit could allow the malicious user to bypass configured file action policies, and traffic that should be dropped could be allowed into the network. Cisco Bug IDs: CSCvf86435.

Vulnerable Product Search on Vulmon Subscribe to Product

cisco firepower_threat_defense 6.2.0.2

cisco firepower_threat_defense 6.2.1

cisco firepower_threat_defense 6.1.0.5

cisco firepower_threat_defense 6.2.2

Vendor Advisories

A vulnerability in the detection engine of Cisco Firepower System Software could allow an unauthenticated, remote attacker to bypass configured file action policies if an Intelligent Application Bypass (IAB) with a drop percentage threshold is also configured The vulnerability is due to incorrect counting of the percentage of dropped traffic An ...