VPN Configuration Management Vulnerability in Cisco FireSIGHT System Software
CVE-2018-0333

5.8MEDIUM

Key Information:

Vendor
Cisco
Vendor
CVE Published:
7 June 2018

Summary

A vulnerability in the VPN configuration management of Cisco FireSIGHT System Software can allow an unauthenticated remote attacker to exploit dynamic configuration changes, leading to the potential bypass of established VPN policies. This issue arises from the incorrect management of configured interface names and VPN parameters during dynamic CLI configuration modifications. By sending specially crafted packets through an affected interface, an attacker may bypass configured VPN security measures, exposing sensitive data and network resources.

Affected Version(s)

Cisco FireSIGHT unknown Cisco FireSIGHT unknown

References

CVSS V3.1

Score:
5.8
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.