PT-2018-1828 · Apple+1 · Apple Macos+1
Published
2018-08-01
·
Updated
2019-10-09
·
CVE-2018-0397
CVSS v2.0
7.1
High
| Vector | AV:N/AC:M/Au:N/C:N/I:N/A:C |
Name of the Vulnerable Software and Affected Versions:
Cisco AMP for Endpoints Mac Connector Software version installed on Apple macOS 10.12
Description:
A vulnerability in the software could allow an unauthenticated, remote attacker to cause a kernel panic on an affected system, resulting in a denial of service (DoS) condition. The issue exists when the software is running in Block network conviction mode. Exploitation could occur if the system starts a server process and an address in the IP blacklist cache attempts to connect to the affected system. A successful exploit could allow the attacker to cause a kernel panic, resulting in a DoS condition. The vulnerability is related to resource management errors.
Recommendations:
For Cisco AMP for Endpoints Mac Connector Software version installed on Apple macOS 10.12, consider disabling the Block network conviction mode as a temporary workaround until a patch is available. Restrict access to the server process to minimize the risk of exploitation. Avoid using the IP blacklist cache in the affected software until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Apple Macos
Cisco Amp For Endpoints Mac Connector