Cisco Firepower Management Center Incomplete Rule Set Vulnerability
The vulnerability is due to a lack of condition checks in the rules engine. An attacker could exploit this vulnerability by spoofing certain Object IDs of Port objects. An exploit could allow the attacker to push an incomplete rule set.
There are no workarounds that address this vulnerability.
This advisory is available at the following link:
http://ift.tt/2kVNvEw
The vulnerability is due to a lack of condition checks in the rules engine. An attacker could exploit this vulnerability by spoofing certain Object IDs of Port objects. An exploit could allow the attacker to push an incomplete rule set.
There are no workarounds that address this vulnerability.
This advisory is available at the following link:
http://ift.tt/2kVNvEw
Security Impact Rating: Medium
CVE: CVE-2017-3809
from Cisco Security Advisory http://ift.tt/2kVNvEw