PT-2018-1828 · Apple+1 · Apple Macos+1

Published

2018-08-01

·

Updated

2019-10-09

·

CVE-2018-0397

CVSS v2.0

7.1

High

VectorAV:N/AC:M/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions: Cisco AMP for Endpoints Mac Connector Software version installed on Apple macOS 10.12
Description: A vulnerability in the software could allow an unauthenticated, remote attacker to cause a kernel panic on an affected system, resulting in a denial of service (DoS) condition. The issue exists when the software is running in Block network conviction mode. Exploitation could occur if the system starts a server process and an address in the IP blacklist cache attempts to connect to the affected system. A successful exploit could allow the attacker to cause a kernel panic, resulting in a DoS condition. The vulnerability is related to resource management errors.
Recommendations: For Cisco AMP for Endpoints Mac Connector Software version installed on Apple macOS 10.12, consider disabling the Block network conviction mode as a temporary workaround until a patch is available. Restrict access to the server process to minimize the risk of exploitation. Avoid using the IP blacklist cache in the affected software until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2018-01430
CVE-2018-0397

Affected Products

Apple Macos
Cisco Amp For Endpoints Mac Connector