CVE-2018-0237 describes a medium-severity vulnerability in Cisco AMP for Endpoints macOS Connector, where an unauthenticated, remote attacker could bypass malware detection. The flaw stems from the software's reliance solely on file extensions for DMG file detection, allowing an attacker to use a nonstandard extension to deliver malicious DMG files. This could lead to malware bypassing configured security measures. While the CVSS score is 5.8, there is no evidence of active exploitation, public exploit code, or significant community discussion surrounding this vulnerability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
1.4\(5\)CPE matchmatch criteria | cpe:2.3:a:cisco:advanced_malware_protection_for_endpoints:1.4\(5\):*:*:*:*:mac_os_x:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.