SSL Decryption Bypass in Cisco Firepower System Software
CVE-2017-6766
What is CVE-2017-6766?
A security flaw in the SSL Decryption and Inspection feature of Cisco Firepower System Software can enable attackers to bypass SSL policies. This vulnerability arises from unexpected interactions between configuration settings related to Known Key and Decrypt and Resign when the software processes abnormal SSL packet headers. By sending a specially crafted SSL packet through a valid session, an unauthenticated, remote attacker can evade the decryption and inspection controls intended to scrutinize network traffic, potentially compromising the integrity of network security measures.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Cisco Firepower System Software Cisco Firepower System Software
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved