2 results (0.001 seconds)

CVSS: 7.5EPSS: 0%CPEs: 7EXPL: 0

07 Aug 2017 — A vulnerability in the Secure Sockets Layer (SSL) Decryption and Inspection feature of Cisco Firepower System Software 5.4.0, 5.4.1, 6.0.0, 6.1.0, 6.2.0, 6.2.1, and 6.2.2 could allow an unauthenticated, remote attacker to bypass the SSL policy for decrypting and inspecting traffic on an affected system. The vulnerability is due to unexpected interaction with Known Key and Decrypt and Resign configuration settings of SSL policies when the affected software receives unexpected SSL packet headers. An attacker ... • https://quickview.cloudapps.cisco.com/quickview/bug/CSCve12652 • CWE-310: Cryptographic Issues •

CVSS: 7.2EPSS: 0%CPEs: 2EXPL: 0

10 Jul 2017 — A vulnerability in the backup and restore functionality of Cisco FireSIGHT System Software could allow an authenticated, local attacker to execute arbitrary code on a targeted system. More Information: CSCvc91092. Known Affected Releases: 6.2.0 6.2.1. Una vulnerabilidad en la funcionalidad backup y restore de Cisco FireSIGHT System Software, podría permitir a un atacante local autenticado ejecutar código arbitrario en un sistema destino. Más información: CSCvc91092. • http://www.securityfocus.com/bid/99460 • CWE-20: Improper Input Validation •