Umbra Wiki cve cve/CVE-2018-0254
Back to wiki

CVE-2018-0254 — NVD record

provenance: imported · CVE: CVE-2018-0254

CVE-2018-0254

NVD vulnerability record

Published 2018-04-19
Last modified 2026-08-11
Status Modified
CVSS v3.0 5.3 MEDIUM
Vector CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
CWE CWE-693

Description

A vulnerability in the detection engine of Cisco Firepower System Software could allow an unauthenticated, remote attacker to bypass configured file action policies if an Intelligent Application Bypass (IAB) with a drop percentage threshold is also configured. The vulnerability is due to incorrect counting of the percentage of dropped traffic. An attacker could exploit this vulnerability by sending network traffic to a targeted device. An exploit could allow the attacker to bypass configured file action policies, and traffic that should be dropped could be allowed into the network. Cisco Bug IDs: CSCvf86435.

References

  • http://www.securityfocus.com/bid/103940
  • https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20180418-fss2
  • http://www.securityfocus.com/bid/103940
  • https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20180418-fss2

Sources

  • NVD detail: https://nvd.nist.gov/vuln/detail/CVE-2018-0254
  • NVD API 2.0: https://services.nvd.nist.gov/rest/json/cves/2.0?cveId=CVE-2018-0254