PT-2018-8737 · Cisco · Cisco Fxos+2

Publicado

2018-06-21

·

Atualizado

2019-10-09

·

CVE-2018-0300

CVSS v2.0

9.0

Alta

VetorAV:N/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions: Cisco Firepower 4100 Series Next-Generation Firewall (NGFW) and Firepower 9300 Security Appliance (affected versions not specified)
Description: A vulnerability in the Cisco FXOS application image upload process could allow an authenticated, remote attacker to create or overwrite arbitrary files on an affected device using path traversal techniques. The issue is due to insufficient validation during the upload process. An attacker could exploit this by creating an application image with malicious code and installing it on the device, potentially allowing the execution of arbitrary code with root privileges. This exploit occurs before signature verification, and a missing or invalid signature in the image will cause the upload to fail but does not prevent the exploit.
Recommendations: At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Path traversal

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2018-0300

Produtos afetados

Cisco Fxos
Cisco Firepower 4100 Series Next-Generation Firewall
Cisco Firepower 9300 Security Appliance