CVE-2018-0138
MEDIUMCisco Firepower System Software - Auth Bypass
Title source: llmDescription
A vulnerability in the detection engine of Cisco Firepower System Software could allow an unauthenticated, remote attacker to bypass file policies that are configured to block files transmitted to an affected device via the BitTorrent protocol. The vulnerability exists because the affected software does not detect BitTorrent handshake messages correctly. An attacker could exploit this vulnerability by sending a crafted BitTorrent connection request to an affected device. A successful exploit could allow the attacker to bypass file policies that are configured to block files transmitted to the affected device via the BitTorrent protocol. Cisco Bug IDs: CSCve26946.
Scores
CVSS v3
5.3
EPSS
0.0023
EPSS Percentile
45.1%
Attack Vector
NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Classification
CWE
CWE-693
Status
published
Affected Products (4)
cisco/firepower_threat_defense
cisco/firepower_threat_defense
cisco/firepower_threat_defense
cisco/firepower_threat_defense
Timeline
Published
Feb 08, 2018
Tracked Since
Feb 18, 2026