Lucene search

K
ciscoCiscoCISCO-SA-20170201-FMC
HistoryFeb 01, 2017 - 4:00 p.m.

Cisco Firepower Management Center Incomplete Rule Set Vulnerability

2017-02-0116:00:00
tools.cisco.com
16

EPSS

0.002

Percentile

53.0%

A vulnerability in the Policy deployment module of the Cisco Firepower Management Center (FMC) could allow an unauthenticated, remote attacker to prevent deployment of a complete and accurate rule base.

The vulnerability is due to a lack of condition checks in the rules engine. An attacker could exploit this vulnerability by spoofing certain Object IDs of Port objects. An exploit could allow the attacker to push an incomplete rule set.

There are no workarounds that address this vulnerability.

This advisory is available at the following link:

https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20170201-fmc[“https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20170201-fmc”]

Affected configurations

Vulners
Node
ciscofirepower_management_centerMatch6.1
OR
ciscofirepower_management_centerMatch6.2
OR
ciscofirepower_management_centerMatch6.1.0
OR
ciscofirepower_management_centerMatch6.2.0
VendorProductVersionCPE
ciscofirepower_management_center6.1cpe:2.3:a:cisco:firepower_management_center:6.1:*:*:*:*:*:*:*
ciscofirepower_management_center6.2cpe:2.3:a:cisco:firepower_management_center:6.2:*:*:*:*:*:*:*
ciscofirepower_management_center6.1.0cpe:2.3:a:cisco:firepower_management_center:6.1.0:*:*:*:*:*:*:*
ciscofirepower_management_center6.2.0cpe:2.3:a:cisco:firepower_management_center:6.2.0:*:*:*:*:*:*:*

EPSS

0.002

Percentile

53.0%

Related for CISCO-SA-20170201-FMC