Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

Test ID:1.3.6.1.4.1.25623.1.0.140272
Category:CISCO
Title:Cisco Firepower Management Secure Sockets Layer Policy Bypass Vulnerability
Summary:A vulnerability in the Secure Sockets Layer (SSL) Decryption and Inspection; feature of Cisco Firepower System Software could allow an unauthenticated, remote attacker to bypass the SSL; policy for decrypting and inspecting traffic on an affected system.
Description:Summary:
A vulnerability in the Secure Sockets Layer (SSL) Decryption and Inspection
feature of Cisco Firepower System Software could allow an unauthenticated, remote attacker to bypass the SSL
policy for decrypting and inspecting traffic on an affected system.

Vulnerability Insight:
The vulnerability is due to unexpected interaction with Known Key and Decrypt
and Resign configuration settings of SSL policies when the affected software receives unexpected SSL packet
headers. An attacker could exploit this vulnerability by sending a crafted SSL packet through an affected device
in a valid SSL session.

Vulnerability Impact:
A successful exploit could allow the attacker to bypass the SSL decryption and
inspection policy for the affected system, which could allow traffic to flow through the system without being
inspected.

Solution:
See the referenced vendor advisory for a solution.

CVSS Score:
5.0

CVSS Vector:
AV:N/AC:L/Au:N/C:N/I:P/A:N

Cross-Ref: Common Vulnerability Exposure (CVE) ID: CVE-2017-6766
CopyrightCopyright (C) 2017 Greenbone AG

This is only one of 145615 vulnerability tests in our test suite. Find out more about running a complete security audit.

To run a free test of this vulnerability against your system, register below.




© 1998-2025 E-Soft Inc. All rights reserved.