Show plain JSON{"configurations": [{"nodes": [{"cpeMatch": [{"criteria": "cpe:2.3:a:cisco:firepower_threat_defense:6.1.0.5:*:*:*:*:*:*:*", "matchCriteriaId": "8C6F9B4F-2837-4034-B45C-C131303FF06B", "vulnerable": true}, {"criteria": "cpe:2.3:a:cisco:firepower_threat_defense:6.2.0.2:*:*:*:*:*:*:*", "matchCriteriaId": "01C9D2DC-17CE-499D-ACF3-BBA75E7AEEE5", "vulnerable": true}, {"criteria": "cpe:2.3:a:cisco:firepower_threat_defense:6.2.1:*:*:*:*:*:*:*", "matchCriteriaId": "AD48BE40-C647-429A-81B6-59E125BBE415", "vulnerable": true}, {"criteria": "cpe:2.3:a:cisco:firepower_threat_defense:6.2.2:*:*:*:*:*:*:*", "matchCriteriaId": "42496A5B-1644-4088-BBCF-2ED810A5694B", "vulnerable": true}], "negate": false, "operator": "OR"}, {"cpeMatch": [{"criteria": "cpe:2.3:h:cisco:amp_7150:-:*:*:*:*:*:*:*", "matchCriteriaId": "1F299F4A-CA8C-46EA-A86F-CA52C182DAE6", "vulnerable": false}, {"criteria": "cpe:2.3:h:cisco:amp_8150:-:*:*:*:*:*:*:*", "matchCriteriaId": "8B6B5352-91B4-4568-A43D-48A534904AAE", "vulnerable": false}, {"criteria": "cpe:2.3:h:cisco:firepower_appliance_7010:-:*:*:*:*:*:*:*", "matchCriteriaId": "BBED4712-39D6-4DFD-B8A5-AF20027DD97E", "vulnerable": false}, {"criteria": "cpe:2.3:h:cisco:firepower_appliance_7020:-:*:*:*:*:*:*:*", "matchCriteriaId": "FF7D9A02-6ED1-4118-9950-8D5537B1DDCA", "vulnerable": false}, {"criteria": "cpe:2.3:h:cisco:firepower_appliance_7030:-:*:*:*:*:*:*:*", "matchCriteriaId": "497E5799-968E-438E-ADE9-205E947A33A9", "vulnerable": false}, {"criteria": "cpe:2.3:h:cisco:firepower_appliance_7050:-:*:*:*:*:*:*:*", "matchCriteriaId": "52AA3762-FFDD-4376-8D79-B393CBFAE23A", "vulnerable": false}, {"criteria": "cpe:2.3:h:cisco:firepower_appliance_7110:-:*:*:*:*:*:*:*", "matchCriteriaId": "5CFB0F77-2A56-439D-87AC-18ED59413F4F", "vulnerable": false}, {"criteria": "cpe:2.3:h:cisco:firepower_appliance_7115:-:*:*:*:*:*:*:*", "matchCriteriaId": "D30DB8A4-83D5-4DA4-8F78-0A7109406E61", "vulnerable": false}, {"criteria": "cpe:2.3:h:cisco:firepower_appliance_7120:-:*:*:*:*:*:*:*", "matchCriteriaId": "483066C8-ED60-456D-B2BE-110524DDE1AA", "vulnerable": false}, {"criteria": "cpe:2.3:h:cisco:firepower_appliance_7125:-:*:*:*:*:*:*:*", "matchCriteriaId": "4FBD966A-B931-475A-924C-C1557B6CE7DB", "vulnerable": false}, {"criteria": "cpe:2.3:h:cisco:firepower_appliance_8120:-:*:*:*:*:*:*:*", "matchCriteriaId": "52DD84FD-BC19-4E94-BBDC-176A38CA95B8", "vulnerable": false}, {"criteria": "cpe:2.3:h:cisco:firepower_appliance_8130:-:*:*:*:*:*:*:*", "matchCriteriaId": "DA4BA4BB-C7AA-4D60-BCCF-733988E954D7", "vulnerable": false}, {"criteria": "cpe:2.3:h:cisco:firepower_appliance_8140:-:*:*:*:*:*:*:*", "matchCriteriaId": "B47B208A-6219-4037-8D9E-1B49C0E70BA7", "vulnerable": false}, {"criteria": "cpe:2.3:h:cisco:firepower_appliance_8250:-:*:*:*:*:*:*:*", "matchCriteriaId": "149B56F8-C51B-4215-A649-9408FD27413D", "vulnerable": false}, {"criteria": "cpe:2.3:h:cisco:firepower_appliance_8260:-:*:*:*:*:*:*:*", "matchCriteriaId": "DB97E4A5-2373-49F3-8A8B-005BAC9BEC32", "vulnerable": false}, {"criteria": "cpe:2.3:h:cisco:firepower_appliance_8270:-:*:*:*:*:*:*:*", "matchCriteriaId": "31B22719-10C9-4FF4-A330-68F0F870FD4E", "vulnerable": false}, {"criteria": "cpe:2.3:h:cisco:firepower_appliance_8290:-:*:*:*:*:*:*:*", "matchCriteriaId": "F78A7356-59B9-4A8D-BBDB-6A70DDA5A183", "vulnerable": false}, {"criteria": "cpe:2.3:h:cisco:firepower_appliance_8350:-:*:*:*:*:*:*:*", "matchCriteriaId": "F7FC1382-F102-4946-A5E5-467D40953637", "vulnerable": false}, {"criteria": "cpe:2.3:h:cisco:firepower_appliance_8360:-:*:*:*:*:*:*:*", "matchCriteriaId": "4F58D55B-E671-44E4-841F-72F95D20C4A7", "vulnerable": false}, {"criteria": "cpe:2.3:h:cisco:firepower_appliance_8370:-:*:*:*:*:*:*:*", "matchCriteriaId": "4A1A5F5A-51F7-4F5D-8901-FA0200602F77", "vulnerable": false}, {"criteria": "cpe:2.3:h:cisco:firepower_appliance_8390:-:*:*:*:*:*:*:*", "matchCriteriaId": "C2AE0775-6C5E-4360-977C-57D9DDD4C9B7", "vulnerable": false}, {"criteria": "cpe:2.3:h:cisco:firepower_management_center_1000:-:*:*:*:*:*:*:*", "matchCriteriaId": "44C4E004-BCBA-4C2A-BBC7-8C6F9E54CC15", "vulnerable": false}, {"criteria": "cpe:2.3:h:cisco:firepower_management_center_2000:-:*:*:*:*:*:*:*", "matchCriteriaId": "A389E5A4-0994-4F75-A264-18371D726ACA", "vulnerable": false}, {"criteria": "cpe:2.3:h:cisco:firepower_management_center_2500:-:*:*:*:*:*:*:*", "matchCriteriaId": "E36B8162-AF24-4538-B81E-6FB95AC221C8", "vulnerable": false}, {"criteria": "cpe:2.3:h:cisco:firepower_management_center_4000:-:*:*:*:*:*:*:*", "matchCriteriaId": "1A9FD1A9-1BB3-4FFB-AB75-5BF8AF61FF1D", "vulnerable": false}, {"criteria": "cpe:2.3:h:cisco:firepower_management_center_4500:-:*:*:*:*:*:*:*", "matchCriteriaId": "05426855-230D-45AA-BD24-DEBBB924C43E", "vulnerable": false}, {"criteria": "cpe:2.3:h:cisco:firesight_management_center_1500:-:*:*:*:*:*:*:*", "matchCriteriaId": "756594F4-D397-425F-ACA3-2E130729B736", "vulnerable": false}, {"criteria": "cpe:2.3:h:cisco:firesight_management_center_3500:-:*:*:*:*:*:*:*", "matchCriteriaId": "B96B6255-BEE7-4AF7-BC82-74CDCBE2BEA1", "vulnerable": false}, {"criteria": "cpe:2.3:h:cisco:firesight_management_center_750:-:*:*:*:*:*:*:*", "matchCriteriaId": "6DE96D31-BB8C-46F0-98F2-903F794C19D9", "vulnerable": false}, {"criteria": "cpe:2.3:h:cisco:ngips_virtual_appliance:-:*:*:*:*:*:*:*", "matchCriteriaId": "34B16156-73F5-4172-ABB1-8BA2F950ABE9", "vulnerable": false}], "negate": false, "operator": "OR"}], "operator": "AND"}], "descriptions": [{"lang": "en", "value": "A vulnerability in the detection engine of Cisco Firepower System Software could allow an unauthenticated, remote attacker to bypass configured file action policies if an Intelligent Application Bypass (IAB) with a drop percentage threshold is also configured. The vulnerability is due to incorrect counting of the percentage of dropped traffic. An attacker could exploit this vulnerability by sending network traffic to a targeted device. An exploit could allow the attacker to bypass configured file action policies, and traffic that should be dropped could be allowed into the network. Cisco Bug IDs: CSCvf86435."}, {"lang": "es", "value": "Una vulnerabilidad en el motor de detecci\u00f3n de Cisco Firepower System Software podr\u00eda permitir que un atacante remoto sin autenticar omita pol\u00edticas de acci\u00f3n de archivos configuradas si un IAB (Intelligent Application Bypass) con un l\u00edmite de porcentaje de anulaci\u00f3n est\u00e1 tambi\u00e9n configurado Esta vulnerabilidad se debe al conteo incorrecto del porcentaje de tr\u00e1fico anulado. Un atacante podr\u00eda explotar esta vulnerabilidad enviando tr\u00e1fico de red a un dispositivo afectado. Su explotaci\u00f3n podr\u00eda permitir que el atacante omita pol\u00edticas de acci\u00f3n de archivos configuradas; el tr\u00e1fico que deber\u00eda omitirse podr\u00eda pasar a la red. Cisco Bug IDs: CSCvf86435."}], "id": "CVE-2018-0254", "lastModified": "2024-11-21T03:37:49.460", "metrics": {"cvssMetricV2": [{"acInsufInfo": true, "baseSeverity": "MEDIUM", "cvssData": {"accessComplexity": "LOW", "accessVector": "NETWORK", "authentication": "NONE", "availabilityImpact": "NONE", "baseScore": 5.0, "confidentialityImpact": "NONE", "integrityImpact": "PARTIAL", "vectorString": "AV:N/AC:L/Au:N/C:N/I:P/A:N", "version": "2.0"}, "exploitabilityScore": 10.0, "impactScore": 2.9, "obtainAllPrivilege": false, "obtainOtherPrivilege": false, "obtainUserPrivilege": false, "source": "nvd@nist.gov", "type": "Primary", "userInteractionRequired": false}], "cvssMetricV30": [{"cvssData": {"attackComplexity": "LOW", "attackVector": "NETWORK", "availabilityImpact": "NONE", "baseScore": 5.3, "baseSeverity": "MEDIUM", "confidentialityImpact": "NONE", "integrityImpact": "LOW", "privilegesRequired": "NONE", "scope": "UNCHANGED", "userInteraction": "NONE", "vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N", "version": "3.0"}, "exploitabilityScore": 3.9, "impactScore": 1.4, "source": "nvd@nist.gov", "type": "Primary"}]}, "published": "2018-04-19T20:29:01.127", "references": [{"source": "ykramarz@cisco.com", "tags": ["Third Party Advisory", "VDB Entry"], "url": "http://www.securityfocus.com/bid/103940"}, {"source": "ykramarz@cisco.com", "tags": ["Vendor Advisory"], "url": "https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20180418-fss2"}, {"source": "af854a3a-2127-422b-91ae-364da2661108", "tags": ["Third Party Advisory", "VDB Entry"], "url": "http://www.securityfocus.com/bid/103940"}, {"source": "af854a3a-2127-422b-91ae-364da2661108", "tags": ["Vendor Advisory"], "url": "https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20180418-fss2"}], "sourceIdentifier": "ykramarz@cisco.com", "vulnStatus": "Modified", "weaknesses": [{"description": [{"lang": "en", "value": "CWE-693"}], "source": "ykramarz@cisco.com", "type": "Secondary"}, {"description": [{"lang": "en", "value": "CWE-693"}], "source": "nvd@nist.gov", "type": "Primary"}]}