Vulnerability in File Type Detection of Cisco Advanced Malware Protection for macOS
CVE-2018-0237
5.8MEDIUM
Summary
The file type detection mechanism in Cisco's Advanced Malware Protection for Endpoints macOS Connector has a critical flaw that can be exploited by attackers. This vulnerability arises from the reliance on file extensions for detecting DMG files. An attacker could circumvent malware detection by sending a DMG file with an unusual extension to the affected device. This exploit allows unauthorized access to potentially harmful files, undermining the security measures intended to protect the system from malware threats.
Affected Version(s)
Cisco AMP for Endpoints Cisco AMP for Endpoints
References
CVSS V3.1
Score:
5.8
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved