CVE-2018-0254: Medium severity Cisco Firepower Threat Defense vulnerability
A vulnerability in the detection engine of Cisco Firepower System Software could allow an unauthenticated, remote attacker to bypass configured file action policies if an Intelligent Application Bypass (IAB) with a drop percentage threshold is also configured. The vulnerability is due to incorrect counting of the percentage of dropped traffic. An attacker could exploit this vulnerability by sending network traffic to a targeted device. An exploit could allow the attacker to bypass configured file action policies, and traffic that should be dropped could be allowed into the network. Cisco Bug IDs: CSCvf86435.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Patch CSCvf86435 - Compensating control
If an Intelligent Application Bypass (IAB) with a drop percentage threshold is configured on Cisco Firepower System Software, adjust or remove the IAB drop percentage threshold configuration to prevent bypass of configured file action policies (CSCvf86435).
- Compensating control
Restrict network access to the targeted Cisco Firepower device so only trusted sources can send traffic that could be used to exploit the detection engine issue (CSCvf86435).
Event History
Frequently Asked Questions
What is the vulnerability ID for this Cisco Firepower System Software vulnerability?
The vulnerability ID for this Cisco Firepower System Software vulnerability is CVE-2018-0254.
What is the severity level of CVE-2018-0254?
The severity level of CVE-2018-0254 is medium with a severity value of 5.3.
How can an attacker exploit CVE-2018-0254?
CVE-2018-0254 can be exploited by an unauthenticated, remote attacker to bypass file action policies if Intelligent Application Bypass (IAB) with a drop percentage threshold is configured.
Which versions of Cisco Firepower Threat Defense are affected by CVE-2018-0254?
CVE-2018-0254 affects Cisco Firepower Threat Defense versions 6.1.0.5, 6.2.0.2, 6.2.1, and 6.2.2.
Where can I find more information about CVE-2018-0254?
You can find more information about CVE-2018-0254 on the Cisco Security Advisory and SecurityFocus websites.