cisco-sa-20180711-firesight-url-bypass: Cisco FireSIGHT System Software URL-Based Access Control Policy Bypass Vulnerability
A vulnerability in the detection engine of Cisco FireSIGHT System Software could allow an unauthenticated, remote attacker to bypass a URL-based access control policy that is configured to block traffic for an affected system. The vulnerability exists because the affected software incorrectly handles TCP packets that are received out of order when a TCP SYN retransmission is issued. An attacker could exploit this vulnerability by sending a maliciously crafted connection through an affected device. A successful exploit could allow the attacker to bypass a URL-based access control policy that is configured to block traffic for the affected system.
There are no workarounds that address this vulnerability. This advisory is available at the following link: https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20180711-firesight-url-bypass
Affected Software
Event History
Frequently Asked Questions
What is the severity of cisco-sa-20180711-firesight-url-bypass?
The severity of the cisco-sa-20180711-firesight-url-bypass vulnerability is considered high as it allows unauthorized access to restricted URLs.
How do I fix cisco-sa-20180711-firesight-url-bypass?
To fix the cisco-sa-20180711-firesight-url-bypass vulnerability, upgrade the Cisco FireSIGHT System Software to the latest version provided by Cisco.
Who is affected by cisco-sa-20180711-firesight-url-bypass?
Any users or organizations using affected versions of Cisco FireSIGHT System Software are vulnerable to cisco-sa-20180711-firesight-url-bypass.
What are the implications of cisco-sa-20180711-firesight-url-bypass?
The implications of cisco-sa-20180711-firesight-url-bypass include potential unauthorized access to sensitive resources and traffic within a network.
Is authentication required to exploit cisco-sa-20180711-firesight-url-bypass?
No, cisco-sa-20180711-firesight-url-bypass can be exploited by an unauthenticated remote attacker.