URL-Based Access Control Bypass in Cisco FireSIGHT System Software
CVE-2018-0384
5.8MEDIUM
What is CVE-2018-0384?
A vulnerability exists in Cisco FireSIGHT System Software where an unauthenticated, remote attacker can bypass URL-based access control policies. This occurs due to improper handling of TCP packets that arrive out of order following TCP SYN retransmissions. An attacker might exploit this flaw by sending specially crafted connections through a compromised device, potentially allowing them to circumvent security measures designed to block unwanted traffic.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Cisco FireSIGHT unknown Cisco FireSIGHT unknown
References
CVSS V3.1
Score:
5.8
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved