Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2019-12701

Опубликовано: 02 окт. 2019
Источник: nvd
CVSS3: 5.8
CVSS3: 5.8
CVSS2: 5
EPSS Низкий

Описание

A vulnerability in the file and malware inspection feature of Cisco Firepower Management Center (FMC) Software could allow an unauthenticated, remote attacker to bypass the file and malware inspection policies on an affected system. The vulnerability exists because the affected software insufficiently validates incoming traffic. An attacker could exploit this vulnerability by sending a crafted HTTP request through an affected device. A successful exploit could allow the attacker to bypass the file and malware inspection policies and send malicious traffic through the affected device.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:cisco:secure_firewall_management_center:-:*:*:*:*:*:*:*
cpe:2.3:a:cisco:vdb_fingerprint_database:*:*:*:*:*:*:*:*
Версия до 327 (исключая)

EPSS

Процентиль: 25%
0.00088
Низкий

5.8 Medium

CVSS3

5.8 Medium

CVSS3

5 Medium

CVSS2

Дефекты

CWE-20
CWE-20

Связанные уязвимости

CVSS3: 5.8
github
больше 3 лет назад

A vulnerability in the file and malware inspection feature of Cisco Firepower Management Center (FMC) Software could allow an unauthenticated, remote attacker to bypass the file and malware inspection policies on an affected system. The vulnerability exists because the affected software insufficiently validates incoming traffic. An attacker could exploit this vulnerability by sending a crafted HTTP request through an affected device. A successful exploit could allow the attacker to bypass the file and malware inspection policies and send malicious traffic through the affected device.

CVSS3: 5.8
fstec
больше 6 лет назад

Уязвимость программного обеспечения администрирования сети Cisco Firepower Management Center (FMC), существующая из-за недостаточной проверки входящего трафика, позволяющая нарушителю обойти политики проверки файлов и вредоносных программ и отправить вредоносный трафик через уязвимое устройство

EPSS

Процентиль: 25%
0.00088
Низкий

5.8 Medium

CVSS3

5.8 Medium

CVSS3

5 Medium

CVSS2

Дефекты

CWE-20
CWE-20