PT-2018-8695 · Cisco · Cisco Firepower System
Published
2018-04-19
·
Updated
2019-10-09
·
CVE-2018-0243
CVSS v3.1
5.8
Medium
| Vector | AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:L/A:N |
Name of the Vulnerable Software and Affected Versions:
Cisco Firepower System Software versions prior to 6.2.3
Description:
A vulnerability in the detection engine could allow an unauthenticated, remote attacker to bypass a configured file action policy intended to drop Server Message Block Version 2 (SMB2) and SMB Version 3 (SMB3) protocols if malware is detected. The issue arises from incorrect detection of an SMB2 or SMB3 file based on the total file length. An attacker could exploit this by sending a crafted SMB2 or SMB3 transfer request, potentially passing SMB2 or SMB3 files that could be malware despite the device being configured to block them. This issue does not affect SMB Version 1 (SMB1) files.
Recommendations:
For versions prior to 6.2.3, update to version 6.2.3 or later to resolve the issue. As a temporary workaround, consider restricting the use of SMB2 and SMB3 protocols until the update can be applied.
Fix
Protection Mechanism Failure
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Cisco Firepower System