Remote File Transfer Vulnerability in Cisco FireSIGHT System Software
CVE-2018-0383

8.6HIGH

Key Information:

Vendor
Cisco
Vendor
CVE Published:
16 July 2018

Summary

A vulnerability in the detection engine of Cisco FireSIGHT System Software could allow an unauthenticated, remote attacker to bypass file policies designed to block certain file transfers via FTP. This flaw arises from improper handling of FTP control connections within the software. By exploiting this vulnerability, an attacker can send a specially crafted FTP connection to upload files to the affected device, evading security measures configured to enforce file transfer restrictions. This poses a significant risk as it undermines the integrity of file policy enforcement.

Affected Version(s)

Cisco FireSIGHT unknown Cisco FireSIGHT unknown

References

CVSS V3.1

Score:
8.6
Severity:
HIGH
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.