Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2018-0237

Опубликовано: 19 апр. 2018
Источник: nvd
CVSS3: 5.8
CVSS2: 5
EPSS Низкий

Описание

A vulnerability in the file type detection mechanism of the Cisco Advanced Malware Protection (AMP) for Endpoints macOS Connector could allow an unauthenticated, remote attacker to bypass malware detection. The vulnerability occurs because the software relies on only the file extension for detecting DMG files. An attacker could exploit this vulnerability by sending a DMG file with a nonstandard extension to a device that is running an affected AMP for Endpoints macOS Connector. An exploit could allow the attacker to bypass configured malware detection. Cisco Bug IDs: CSCve34034.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:cisco:advanced_malware_protection_for_endpoints:1.4\(5\):*:*:*:*:mac_os_x:*:*

EPSS

Процентиль: 69%
0.00606
Низкий

5.8 Medium

CVSS3

5 Medium

CVSS2

Дефекты

CWE-20
CWE-706

Связанные уязвимости

CVSS3: 5.8
github
больше 3 лет назад

A vulnerability in the file type detection mechanism of the Cisco Advanced Malware Protection (AMP) for Endpoints macOS Connector could allow an unauthenticated, remote attacker to bypass malware detection. The vulnerability occurs because the software relies on only the file extension for detecting DMG files. An attacker could exploit this vulnerability by sending a DMG file with a nonstandard extension to a device that is running an affected AMP for Endpoints macOS Connector. An exploit could allow the attacker to bypass configured malware detection. Cisco Bug IDs: CSCve34034.

EPSS

Процентиль: 69%
0.00606
Низкий

5.8 Medium

CVSS3

5 Medium

CVSS2

Дефекты

CWE-20
CWE-706