CVE-2019-1672
Cisco Web Security Appliance Decryption Policy Bypass Vulnerability
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
A vulnerability in the Decryption Policy Default Action functionality of the Cisco Web Security Appliance (WSA) could allow an unauthenticated, remote attacker to bypass a configured drop policy and allow traffic onto the network that should have been denied. The vulnerability is due to the incorrect handling of SSL-encrypted traffic when Decrypt for End-User Notification is disabled in the configuration. An attacker could exploit this vulnerability by sending a SSL connection through the affected device. A successful exploit could allow the attacker to bypass a configured drop policy to block specific SSL connections. Releases 10.1.x and 10.5.x are affected.
Una vulnerabilidad en la funcionalidad Decryption Policy Default Action de Cisco Web Security Appliance (WSA) podría permitir que un atacante remoto no autenticado omita una política de anulación configurada y permita el tráfico en la red que debería no estar permitido. Esta vulnerabilidad se debe a la gestión inadecuada del tráfico cifrado por SSL cuando las notificaciones "Decrypt for End-User" están deshabilitadas en la configuración. Un atacante podría explotar esta vulnerabilidad enviando una conexión SSL a través de un dispositivo afectado. Su explotación con éxito podría permitir que el atacante omita una política de anulación configurada para bloquear conexiones SSL concretas. Las versiones 10.1.x y 10.5.x se han visto afectadas.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2018-12-06 CVE Reserved
- 2019-02-08 CVE Published
- 2024-06-29 EPSS Updated
- 2024-09-16 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-400: Uncontrolled Resource Consumption
CAPEC
References (2)
URL | Tag | Source |
---|---|---|
http://www.securityfocus.com/bid/106904 | Third Party Advisory |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Cisco Search vendor "Cisco" | Web Security Appliance Search vendor "Cisco" for product "Web Security Appliance" | 10.1.0-204 Search vendor "Cisco" for product "Web Security Appliance" and version "10.1.0-204" | - |
Affected
| ||||||
Cisco Search vendor "Cisco" | Web Security Appliance Search vendor "Cisco" for product "Web Security Appliance" | 10.5.2-072 Search vendor "Cisco" for product "Web Security Appliance" and version "10.5.2-072" | - |
Affected
| ||||||
Cisco Search vendor "Cisco" | Web Security Appliance Search vendor "Cisco" for product "Web Security Appliance" | 11.5.1-fcs-115 Search vendor "Cisco" for product "Web Security Appliance" and version "11.5.1-fcs-115" | - |
Affected
|