CVE-2018-0254
A vulnerability in the detection engine of Cisco Firepower System Software could allow an unauthenticated, remote attacker to bypass configured file action policies if an Intelligent Application Bypass (IAB) with a drop percentage threshold is also configured. The vulnerability is due to incorrect counting of the percentage of dropped traffic. An attacker could exploit this vulnerability by sending network traffic to a targeted device. An exploit could allow the attacker to bypass configured file action policies, and traffic that should be dropped could be allowed into the network. Cisco Bug IDs: CSCvf86435.
CVSS
- Versión: 3.0
- Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
- Puntuación base: 5.3
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 1.16%
- Percentil entre todas las CVEs puntuadas: 66
- Fecha de la puntuación: 7/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
CWE
- CWE-693
- CWE-693
Referencias
JSON original (NVD)
Mostrar
{
"id": "CVE-2018-0254",
"cveTags": [],
"metrics": {
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2018-0254",
"role": "CISA Coordinator",
"options": [
{
"exploitation": "none"
},
{
"automatable": "yes"
},
{
"technicalImpact": "partial"
}
],
"version": "2.0.3",
"timestamp": "2024-11-29T14:44:20.614528Z"
}
}
],
"cvssMetricV2": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"version": "2.0",
"baseScore": 5,
"accessVector": "NETWORK",
"vectorString": "AV:N/AC:L/Au:N/C:N/I:P/A:N",
"authentication": "NONE",
"integrityImpact": "PARTIAL",
"accessComplexity": "LOW",
"availabilityImpact": "NONE",
"confidentialityImpact": "NONE"
},
"acInsufInfo": true,
"impactScore": 2.9,
"baseSeverity": "MEDIUM",
"obtainAllPrivilege": false,
"exploitabilityScore": 10,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
],
"cvssMetricV30": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.0",
"baseScore": 5.3,
"attackVector": "NETWORK",
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N",
"integrityImpact": "LOW",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "NONE",
"privilegesRequired": "NONE",
"confidentialityImpact": "NONE"
},
"impactScore": 1.4,
"exploitabilityScore": 3.9
}
]
},
"affected": [
{
"source": "psirt@cisco.com",
"affectedData": [
{
"vendor": "n/a",
"product": "Cisco Firepower System Software",
"versions": [
{
"status": "affected",
"version": "Cisco Firepower System Software"
}
]
}
]
}
],
"published": "2018-04-19T20:29:01.127",
"references": [
{
"url": "http://www.securityfocus.com/bid/103940",
"tags": [
"Third Party Advisory",
"VDB Entry"
],
"source": "psirt@cisco.com"
},
{
"url": "https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20180418-fss2",
"tags": [
"Vendor Advisory"
],
"source": "psirt@cisco.com"
},
{
"url": "http://www.securityfocus.com/bid/103940",
"tags": [
"Third Party Advisory",
"VDB Entry"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20180418-fss2",
"tags": [
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Secondary",
"source": "psirt@cisco.com",
"description": [
{
"lang": "en",
"value": "CWE-693"
}
]
},
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "CWE-693"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "A vulnerability in the detection engine of Cisco Firepower System Software could allow an unauthenticated, remote attacker to bypass configured file action policies if an Intelligent Application Bypass (IAB) with a drop percentage threshold is also configured. The vulnerability is due to incorrect counting of the percentage of dropped traffic. An attacker could exploit this vulnerability by sending network traffic to a targeted device. An exploit could allow the attacker to bypass configured file action policies, and traffic that should be dropped could be allowed into the network. Cisco Bug IDs: CSCvf86435."
},
{
"lang": "es",
"value": "Una vulnerabilidad en el motor de detección de Cisco Firepower System Software podría permitir que un atacante remoto sin autenticar omita políticas de acción de archivos configuradas si un IAB (Intelligent Application Bypass) con un límite de porcentaje de anulación está también configurado Esta vulnerabilidad se debe al conteo incorrecto del porcentaje de tráfico anulado. Un atacante podría explotar esta vulnerabilidad enviando tráfico de red a un dispositivo afectado. Su explotación podría permitir que el atacante omita políticas de acción de archivos configuradas; el tráfico que debería omitirse podría pasar a la red. Cisco Bug IDs: CSCvf86435."
}
],
"lastModified": "2026-08-11T19:33:44.513",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:cisco:secure_firewall_threat_defense:6.1.0.5:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "D003A3CA-955E-4652-A1A1-F18D571E655C"
},
{
"criteria": "cpe:2.3:a:cisco:secure_firewall_threat_defense:6.2.0.2:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "342C8398-E680-455E-AE9A-462550C87D8E"
},
{
"criteria": "cpe:2.3:a:cisco:secure_firewall_threat_defense:6.2.1:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "7BA76F3F-8B12-437F-A70A-2EFE639FA86E"
},
{
"criteria": "cpe:2.3:a:cisco:secure_firewall_threat_defense:6.2.2:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "6E8F4132-FCC6-4C3E-A7B9-7DDA6F9C0315"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:cisco:amp_7150:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "1F299F4A-CA8C-46EA-A86F-CA52C182DAE6"
},
{
"criteria": "cpe:2.3:h:cisco:amp_8150:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "8B6B5352-91B4-4568-A43D-48A534904AAE"
},
{
"criteria": "cpe:2.3:h:cisco:firepower_appliance_7010:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "BBED4712-39D6-4DFD-B8A5-AF20027DD97E"
},
{
"criteria": "cpe:2.3:h:cisco:firepower_appliance_7020:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "FF7D9A02-6ED1-4118-9950-8D5537B1DDCA"
},
{
"criteria": "cpe:2.3:h:cisco:firepower_appliance_7030:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "497E5799-968E-438E-ADE9-205E947A33A9"
},
{
"criteria": "cpe:2.3:h:cisco:firepower_appliance_7050:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "52AA3762-FFDD-4376-8D79-B393CBFAE23A"
},
{
"criteria": "cpe:2.3:h:cisco:firepower_appliance_7110:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "5CFB0F77-2A56-439D-87AC-18ED59413F4F"
},
{
"criteria": "cpe:2.3:h:cisco:firepower_appliance_7115:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "D30DB8A4-83D5-4DA4-8F78-0A7109406E61"
},
{
"criteria": "cpe:2.3:h:cisco:firepower_appliance_7120:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "483066C8-ED60-456D-B2BE-110524DDE1AA"
},
{
"criteria": "cpe:2.3:h:cisco:firepower_appliance_7125:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "4FBD966A-B931-475A-924C-C1557B6CE7DB"
},
{
"criteria": "cpe:2.3:h:cisco:firepower_appliance_8120:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "52DD84FD-BC19-4E94-BBDC-176A38CA95B8"
},
{
"criteria": "cpe:2.3:h:cisco:firepower_appliance_8130:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "DA4BA4BB-C7AA-4D60-BCCF-733988E954D7"
},
{
"criteria": "cpe:2.3:h:cisco:firepower_appliance_8140:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "B47B208A-6219-4037-8D9E-1B49C0E70BA7"
},
{
"criteria": "cpe:2.3:h:cisco:firepower_appliance_8250:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "149B56F8-C51B-4215-A649-9408FD27413D"
},
{
"criteria": "cpe:2.3:h:cisco:firepower_appliance_8260:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "DB97E4A5-2373-49F3-8A8B-005BAC9BEC32"
},
{
"criteria": "cpe:2.3:h:cisco:firepower_appliance_8270:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "31B22719-10C9-4FF4-A330-68F0F870FD4E"
},
{
"criteria": "cpe:2.3:h:cisco:firepower_appliance_8290:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "F78A7356-59B9-4A8D-BBDB-6A70DDA5A183"
},
{
"criteria": "cpe:2.3:h:cisco:firepower_appliance_8350:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "F7FC1382-F102-4946-A5E5-467D40953637"
},
{
"criteria": "cpe:2.3:h:cisco:firepower_appliance_8360:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "4F58D55B-E671-44E4-841F-72F95D20C4A7"
},
{
"criteria": "cpe:2.3:h:cisco:firepower_appliance_8370:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "4A1A5F5A-51F7-4F5D-8901-FA0200602F77"
},
{
"criteria": "cpe:2.3:h:cisco:firepower_appliance_8390:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "C2AE0775-6C5E-4360-977C-57D9DDD4C9B7"
},
{
"criteria": "cpe:2.3:h:cisco:firepower_management_center_1000:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "44C4E004-BCBA-4C2A-BBC7-8C6F9E54CC15"
},
{
"criteria": "cpe:2.3:h:cisco:firepower_management_center_2000:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "A389E5A4-0994-4F75-A264-18371D726ACA"
},
{
"criteria": "cpe:2.3:h:cisco:firepower_management_center_2500:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "E36B8162-AF24-4538-B81E-6FB95AC221C8"
},
{
"criteria": "cpe:2.3:h:cisco:firepower_management_center_4000:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "1A9FD1A9-1BB3-4FFB-AB75-5BF8AF61FF1D"
},
{
"criteria": "cpe:2.3:h:cisco:firepower_management_center_4500:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "05426855-230D-45AA-BD24-DEBBB924C43E"
},
{
"criteria": "cpe:2.3:h:cisco:firesight_management_center_1500:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "756594F4-D397-425F-ACA3-2E130729B736"
},
{
"criteria": "cpe:2.3:h:cisco:firesight_management_center_3500:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "B96B6255-BEE7-4AF7-BC82-74CDCBE2BEA1"
},
{
"criteria": "cpe:2.3:h:cisco:firesight_management_center_750:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "6DE96D31-BB8C-46F0-98F2-903F794C19D9"
},
{
"criteria": "cpe:2.3:h:cisco:ngips_virtual_appliance:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "34B16156-73F5-4172-ABB1-8BA2F950ABE9"
}
],
"operator": "OR"
}
],
"operator": "AND"
}
],
"sourceIdentifier": "psirt@cisco.com"
}