Lucene search

K
ciscoCiscoCISCO-SA-20151116-FIRE
HistoryNov 17, 2015 - 12:00 a.m.

Cisco Firepower 9000 USB Kernel Denial of Service Vulnerability

2015-11-1700:00:00
tools.cisco.com
15

CVSS2

4.9

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

COMPLETE

AV:L/AC:L/Au:N/C:N/I:N/A:C

EPSS

0

Percentile

12.6%

A vulnerability in the USB driver of Cisco Firepower 9000 could allow an unauthenticated, local attacker with physical access to the device to send invalid USB commands to the kernel and cause a denial of service (DoS) condition.

The vulnerability is due to insufficient sanitization of USB input parameters. An attacker could exploit this vulnerability by using crafted USB user inputs to send invalid USB commands to the kernel.

Cisco has not released software updates that address this vulnerability. Workarounds that mitigate this vulnerability are not available.

This advisory is available at the following link: https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20151116-fire[“https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20151116-fire”]

Affected configurations

Vulners
Node
ciscofirepower_extensible_operating_systemMatchany
OR
ciscofirepower_extensible_operating_systemMatchany
VendorProductVersionCPE
ciscofirepower_extensible_operating_systemanycpe:2.3:o:cisco:firepower_extensible_operating_system:any:*:*:*:*:*:*:*

CVSS2

4.9

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

COMPLETE

AV:L/AC:L/Au:N/C:N/I:N/A:C

EPSS

0

Percentile

12.6%

Related for CISCO-SA-20151116-FIRE