PT-2018-8796 · Cisco · Cisco Firepower System+1
Published
2018-07-16
·
Updated
2024-11-26
·
CVE-2018-0370
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
Cisco Firepower System Software (affected versions not specified)
Description
A vulnerability in the detection engine could allow an unauthenticated, remote attacker to cause one of the detection engine processes to run out of memory, slowing down traffic processing. This issue is due to improper handling of traffic when the Secure Sockets Layer (SSL) inspection policy is enabled. An attacker could exploit this by sending malicious traffic through an affected device, increasing the resource consumption of a single instance of the Snort detection engine, leading to performance degradation and eventually the restart of the affected Snort process.
Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Cisco Firepower System
Snort