CVE-2019-12696

HIGH

Cisco Firepower - Unauthenticated Malware and File Policy Bypass for RTF and RAR Files

Title source: llm
STIX 2.1

Description

Multiple vulnerabilities in the Cisco Firepower System Software Detection Engine could allow an unauthenticated, remote attacker to bypass configured Malware and File Policies for RTF and RAR file types. For more information about these vulnerabilities, see the Details section of this advisory.

References (1)

Core 1
Core References

Scores

CVSS v3 7.5
EPSS 0.0146
EPSS Percentile 70.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact partial

Details

CWE
CWE-693
Status published
Products (4)
cisco/firepower 6.2.3.1
cisco/firepower 6.2.3.7
cisco/firepower 6.3.0
cisco/firepower 6.4.0
Published Oct 02, 2019
Tracked Since Feb 18, 2026