CVE-2018-0272
 
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
A vulnerability in the Secure Sockets Layer (SSL) Engine of Cisco Firepower System Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition. The vulnerability is due to improper error handling while processing SSL traffic. An attacker could exploit this vulnerability by sending a large volume of crafted SSL traffic to the vulnerable device. A successful exploit could allow the attacker to degrade the device performance by triggering a persistent high CPU utilization condition. Cisco Bug IDs: CSCvh89340.
Una vulnerabilidad en el motor Secure Sockets Layer (SSL) de Cisco Firepower System Software podría permitir que un atacante remoto no autenticado provoque una condición de denegación de servicio (DoS). La vulnerabilidad se debe al procesamiento incorrecto de errores al procesar tráfico SSL. Un atacante podría explotar esta vulnerabilidad mediante el envío de un gran volumen de tráfico SSL manipulado al dispositivo objetivo. Su explotación con éxito podría permitir que el atacante degrade el rendimiento del dispositivo desencadenando una condición de uso alto de CPU persistente. Cisco Bug IDs: CSCvh89340.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2017-11-27 CVE Reserved
- 2018-04-19 CVE Published
- 2024-02-27 EPSS Updated
- 2024-08-05 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-399: Resource Management Errors
- CWE-755: Improper Handling of Exceptional Conditions
CAPEC
References (2)
URL | Tag | Source |
---|---|---|
http://www.securityfocus.com/bid/103925 | Third Party Advisory |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Cisco Search vendor "Cisco" | Firepower Search vendor "Cisco" for product "Firepower" | 6.2.1 Search vendor "Cisco" for product "Firepower" and version "6.2.1" | - |
Affected
| ||||||
Cisco Search vendor "Cisco" | Firepower Search vendor "Cisco" for product "Firepower" | 6.2.2.1 Search vendor "Cisco" for product "Firepower" and version "6.2.2.1" | - |
Affected
|