Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2018-0333

Опубликовано: 07 июн. 2018
Источник: nvd
CVSS3: 5.8
CVSS2: 5
EPSS Низкий

Описание

A vulnerability in the VPN configuration management of Cisco FireSIGHT System Software could allow an unauthenticated, remote attacker to bypass VPN security due to unintended side effects of dynamic configuration changes that could allow an attacker to bypass configured policies. The vulnerability is due to incorrect management of the configured interface names and VPN parameters when dynamic CLI configuration changes are performed. An attacker could exploit this vulnerability by sending packets through an interface on the targeted device. A successful exploit could allow the attacker to bypass configured VPN policies. Cisco Bug IDs: CSCvh49388.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:cisco:secure_firewall_management_center:6.2.2:*:*:*:*:*:*:*

EPSS

Процентиль: 38%
0.00169
Низкий

5.8 Medium

CVSS3

5 Medium

CVSS2

Дефекты

CWE-693
CWE-693

Связанные уязвимости

CVSS3: 5.8
github
больше 3 лет назад

A vulnerability in the VPN configuration management of Cisco FireSIGHT System Software could allow an unauthenticated, remote attacker to bypass VPN security due to unintended side effects of dynamic configuration changes that could allow an attacker to bypass configured policies. The vulnerability is due to incorrect management of the configured interface names and VPN parameters when dynamic CLI configuration changes are performed. An attacker could exploit this vulnerability by sending packets through an interface on the targeted device. A successful exploit could allow the attacker to bypass configured VPN policies. Cisco Bug IDs: CSCvh49388.

EPSS

Процентиль: 38%
0.00169
Низкий

5.8 Medium

CVSS3

5 Medium

CVSS2

Дефекты

CWE-693
CWE-693