漏洞标题
Cisco Firepower Threat Defense Software Ethernet Industrial Protocol Policy 绕过漏洞
漏洞描述信息
思科Firepower威胁防御软件以太网工业协议策略绕过漏洞
CVSS信息
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
漏洞类别
N/A
漏洞标题
Cisco Firepower Threat Defense Software Ethernet Industrial Protocol Policy Bypass Vulnerabilities
漏洞描述信息
Multiple vulnerabilities in the payload inspection for Ethernet Industrial Protocol (ENIP) traffic for Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to bypass configured rules for ENIP traffic. These vulnerabilities are due to incomplete processing during deep packet inspection for ENIP packets. An attacker could exploit these vulnerabilities by sending a crafted ENIP packet to the targeted interface. A successful exploit could allow the attacker to bypass configured access control and intrusion policies that should be activated for the ENIP packet.
CVSS信息
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:L/A:N
漏洞类别
访问控制不恰当
漏洞标题
Cisco Firepower Threat Defense 访问控制错误漏洞
漏洞描述信息
Cisco Firepower Threat Defense(FTD)是美国思科(Cisco)公司的一套提供下一代防火墙服务的统一软件。 Cisco Firepower Threat Defense Software 存在安全漏洞,该漏洞源于在对 ENIP 数据包进行深度数据包检查期间处理不完整造成的。攻击者可以通过向目标接口发送精心制作的 ENIP 数据包来利用这些漏洞。成功的利用可能允许攻击者绕过应该为 ENIP 数据包激活的配置访问控制和入侵策略。
CVSS信息
N/A
漏洞类别
授权问题