// For flags

CVE-2018-0300

 

Severity Score

7.2
*CVSS v3

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

0
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

A vulnerability in the process of uploading new application images to Cisco FXOS on the Cisco Firepower 4100 Series Next-Generation Firewall (NGFW) and Firepower 9300 Security Appliance could allow an authenticated, remote attacker using path traversal techniques to create or overwrite arbitrary files on an affected device. The vulnerability is due to insufficient validation during the application image upload process. An attacker could exploit this vulnerability by creating an application image containing malicious code and installing the image on the affected device using the CLI or web-based user interface (web UI). These actions occur prior to signature verification and could allow the attacker to create and execute arbitrary code with root privileges. Note: A missing or invalid signature in the application image will cause the upload process to fail, but does not prevent the exploit. Cisco Bug IDs: CSCvc21901.

Una vulnerabilidad en el proceso de subida de nuevas imágenes de aplicación en Cisco FXOS en Cisco Firepower 4100 Series Next-Generation Firewall (NGFW) y Firepower 9300 Security Appliance podría permitir que un atacante remoto autenticado emplee técnicas de salto de directorio para crear o sobrescribir archivos arbitrarios en un dispositivo afectado. La vulnerabilidad se debe a una validación insuficiente durante el proceso de subida de imágenes de aplicación. Un atacante podría explotar esta vulnerabilidad mediante la creación de una imagen de aplicación que contiene código malicioso e instalando la imagen en el dispositivo afectado mediante la interfaz de línea de comandos o una interfaz de usuario web. Estas acciones ocurren antes de la verificación de firmas y podrían permitir que el atacante cree y ejecute código arbitrario con privilegios root. Nota: una firma no válida o la falta de firma en la imagen de la aplicación provocará que el proceso de subida fracase, pero no evita el exploit. Cisco Bug IDs: CSCvc21901.

*Credits: N/A
CVSS Scores
Attack Vector
Network
Attack Complexity
Low
Privileges Required
High
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High
Attack Vector
Network
Attack Complexity
Low
Authentication
Single
Confidentiality
Complete
Integrity
Complete
Availability
Complete
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2017-11-27 CVE Reserved
  • 2018-06-21 CVE Published
  • 2024-08-05 CVE Updated
  • 2024-09-24 EPSS Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
  • ---------- First Exploit
CWE
  • CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CAPEC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Cisco
Search vendor "Cisco"
Fxos
Search vendor "Cisco" for product "Fxos"
2.0\(1.68\)
Search vendor "Cisco" for product "Fxos" and version "2.0\(1.68\)"
-
Affected
in Cisco
Search vendor "Cisco"
Firepower 4110
Search vendor "Cisco" for product "Firepower 4110"
--
Safe
Cisco
Search vendor "Cisco"
Fxos
Search vendor "Cisco" for product "Fxos"
2.0\(1.68\)
Search vendor "Cisco" for product "Fxos" and version "2.0\(1.68\)"
-
Affected
in Cisco
Search vendor "Cisco"
Firepower 4120
Search vendor "Cisco" for product "Firepower 4120"
--
Safe
Cisco
Search vendor "Cisco"
Fxos
Search vendor "Cisco" for product "Fxos"
2.0\(1.68\)
Search vendor "Cisco" for product "Fxos" and version "2.0\(1.68\)"
-
Affected
in Cisco
Search vendor "Cisco"
Firepower 4140
Search vendor "Cisco" for product "Firepower 4140"
--
Safe
Cisco
Search vendor "Cisco"
Fxos
Search vendor "Cisco" for product "Fxos"
2.0\(1.68\)
Search vendor "Cisco" for product "Fxos" and version "2.0\(1.68\)"
-
Affected
in Cisco
Search vendor "Cisco"
Firepower 4150
Search vendor "Cisco" for product "Firepower 4150"
--
Safe
Cisco
Search vendor "Cisco"
Fxos
Search vendor "Cisco" for product "Fxos"
2.0\(1.68\)
Search vendor "Cisco" for product "Fxos" and version "2.0\(1.68\)"
-
Affected
in Cisco
Search vendor "Cisco"
Firepower 9300 Security Appliance
Search vendor "Cisco" for product "Firepower 9300 Security Appliance"
--
Safe