CVE-2019-1978 describes a medium-severity vulnerability in the stream reassembly component of Cisco Firepower Threat Defense Software, FirePOWER Services Software for ASA, and Firepower Management Center Software. An unauthenticated, remote attacker can exploit this flaw by sending crafted traffic streams, bypassing filtering protections and delivering malicious requests to protected systems. The vulnerability has a CVSS score of 5.8 (MEDIUM) and a FAUCET Risk Score of 97/100, indicating a significant risk despite its medium CVSS. While not listed on the KEV catalog and lacking public Metasploit or Nuclei exploits, it has garnered substantial community discussion and media coverage, though the provided articles seem to be about ransomware and not directly related to this specific CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
All Versions ImpactedCPE matchmatch criteria | cpe:2.3:a:cisco:firepower_services_software_for_asa:*:*:*:*:*:*:*:* | ||
All Versions ImpactedCPE matchmatch criteria | cpe:2.3:a:cisco:firepower_threat_defense:*:*:*:*:*:*:*:* | ||
>= 2.9.12, <= 2.9.12.15CPE matchmatch criteria | cpe:2.3:a:cisco:secure_firewall_management_center:*:*:*:*:*:*:*:* | ||
>= 2.9.13, <= 2.9.13.6CPE matchmatch criteria | cpe:2.3:a:cisco:secure_firewall_management_center:*:*:*:*:*:*:*:* | ||
>= 2.9.14.0, <= 2.9.14.5CPE matchmatch criteria | cpe:2.3:a:cisco:secure_firewall_management_center:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.