CVE-2018-0383 describes a high-severity vulnerability in the detection engine of Cisco FireSIGHT System Software, specifically affecting Cisco Secure Firewall Management Center. This flaw allows an unauthenticated, remote attacker to bypass file policies designed to block FTP file transfers. The vulnerability stems from incorrect handling of FTP control connections, enabling an attacker to transfer files despite blocking policies. With a CVSS score of 8.6, the attack vector is network-based with low complexity and no user interaction, leading to a high impact on integrity by allowing unauthorized file uploads. There is no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
6.2.2.1CPE matchmatch criteria | cpe:2.3:a:cisco:secure_firewall_management_center:6.2.2.1:*:*:*:*:*:*:* | ||
6.2.3CPE matchmatch criteria | cpe:2.3:a:cisco:secure_firewall_management_center:6.2.3:*:*:*:*:*:*:* | ||
6.3.0CPE matchmatch criteria | cpe:2.3:a:cisco:secure_firewall_management_center:6.3.0:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.