Lucene search

K
nvd[email protected]NVD:CVE-2017-12300
HistoryNov 16, 2017 - 7:29 a.m.

CVE-2017-12300

2017-11-1607:29:00
CWE-20
web.nvd.nist.gov
5

CVSS2

5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:L/Au:N/C:N/I:P/A:N

CVSS3

5.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

CHANGED

Confidentiality Impact

NONE

Integrity Impact

LOW

Availability Impact

NONE

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:L/A:N

AI Score

5.7

Confidence

High

EPSS

0.001

Percentile

40.1%

A vulnerability in the SNORT detection engine of Cisco Firepower System Software could allow an unauthenticated, remote attacker to bypass a file policy that is configured to block the Server Message Block Version 2 (SMB2) protocol. The vulnerability is due to the incorrect detection of an SMB2 file when the detection is based on the length of the file. An attacker could exploit this vulnerability by sending a crafted SMB2 transfer request through the targeted device. A successful exploit could allow the attacker to bypass filters that are configured to block SMB2 traffic. Cisco Bug IDs: CSCve58398.

Affected configurations

Nvd
Node
ciscofirepower_management_centerMatch2.9.9
OR
ciscofirepower_management_centerMatch2.9.10
OR
ciscofirepower_management_centerMatch2.9.11
OR
ciscofirepower_management_centerMatch2.9.12
VendorProductVersionCPE
ciscofirepower_management_center2.9.9cpe:2.3:a:cisco:firepower_management_center:2.9.9:*:*:*:*:*:*:*
ciscofirepower_management_center2.9.10cpe:2.3:a:cisco:firepower_management_center:2.9.10:*:*:*:*:*:*:*
ciscofirepower_management_center2.9.11cpe:2.3:a:cisco:firepower_management_center:2.9.11:*:*:*:*:*:*:*
ciscofirepower_management_center2.9.12cpe:2.3:a:cisco:firepower_management_center:2.9.12:*:*:*:*:*:*:*

CVSS2

5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:L/Au:N/C:N/I:P/A:N

CVSS3

5.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

CHANGED

Confidentiality Impact

NONE

Integrity Impact

LOW

Availability Impact

NONE

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:L/A:N

AI Score

5.7

Confidence

High

EPSS

0.001

Percentile

40.1%

Related for NVD:CVE-2017-12300