CVE-2018-0244: Medium severity Cisco Firepower Threat Defense vulnerability
A vulnerability in the detection engine of Cisco Firepower System Software could allow an unauthenticated, remote attacker to bypass a configured file action policy to drop the Server Message Block (SMB) protocol if a malware file is detected. The vulnerability is due to how the SMB protocol handles a case in which a large file transfer fails. This case occurs when some pieces of the file are successfully transferred to the remote endpoint, but ultimately the file transfer fails and is reset. An attacker could exploit this vulnerability by sending a crafted SMB file transfer request through the targeted device. An exploit could allow the attacker to pass an SMB file that contains malware, which the device is configured to block. This vulnerability affects Cisco Firepower System Software when one or more file action policies are configured, on software releases prior to 6.2.3. Cisco Bug IDs: CSCvc20141.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Cisco Firepower System Softwareto a version that resolves this vulnerability.Fixed in 6.2.3 - Compensating control
If upgrade to 6.2.3 or later is not immediately possible, mitigate by preventing SMB file transfer requests from reaching the affected Cisco Firepower device (e.g., block SMB traffic at network controls for the device path).
- Operational
Review and, if needed, re-verify configured file action policies after upgrading to 6.2.3 or later to ensure malware files are correctly blocked as intended.
Event History
Frequently Asked Questions
What is the severity of CVE-2018-0244?
CVE-2018-0244 is rated as a high severity vulnerability.
How do I fix CVE-2018-0244?
To fix CVE-2018-0244, update to a patched version of Cisco Firepower System Software that is higher than 6.2.3.
Which Cisco products are affected by CVE-2018-0244?
CVE-2018-0244 affects the Cisco Firepower Threat Defense up to version 6.2.3.
Can CVE-2018-0244 be exploited remotely?
Yes, CVE-2018-0244 can be exploited by an unauthenticated remote attacker.
What type of attack can CVE-2018-0244 facilitate?
CVE-2018-0244 can allow an attacker to bypass file action policies related to the SMB protocol.