cve,link,title,description,vendor,products,score,severity,epss,cisa,cisa_published,article,ransomware,exploited,exploited_date,poc,trended,trended_no_1,trended_no_1_date,published,trended_score CVE-2019-12696,https://securityvulnerability.io/vulnerability/CVE-2019-12696,Cisco Firepower System Software Detection Engine RTF and RAR Malware and File Policy Bypass Vulnerabilities,"Multiple vulnerabilities in the Cisco Firepower System Software Detection Engine could allow an unauthenticated, remote attacker to bypass configured Malware and File Policies for RTF and RAR file types. For more information about these vulnerabilities, see the Details section of this advisory.",Cisco,Cisco Firesight System Software,5.8,MEDIUM,0.00139999995008111,false,,false,false,true,2024-09-17T03:17:16.000Z,,false,false,,2019-10-02T00:00:00.000Z,0 CVE-2019-12697,https://securityvulnerability.io/vulnerability/CVE-2019-12697,Cisco Firepower System Software Detection Engine RTF and RAR Malware and File Policy Bypass Vulnerabilities,"Multiple vulnerabilities in the Cisco Firepower System Software Detection Engine could allow an unauthenticated, remote attacker to bypass configured Malware and File Policies for RTF and RAR file types. For more information about these vulnerabilities, see the Details section of this advisory.",Cisco,Cisco Firesight System Software,5.8,MEDIUM,0.00139999995008111,false,,false,false,true,2024-09-16T18:16:26.000Z,,false,false,,2019-10-02T00:00:00.000Z,0 CVE-2018-0455,https://securityvulnerability.io/vulnerability/CVE-2018-0455,Cisco Firepower System Software Detection Engine Denial of Service Vulnerability,"A vulnerability in the Server Message Block Version 2 (SMBv2) and Version 3 (SMBv3) protocol implementation for the Cisco Firepower System Software could allow an unauthenticated, remote attacker to cause the device to run low on system memory, possibly preventing the device from forwarding traffic. It is also possible that a manual reload of the device may be required to clear the condition. The vulnerability is due to incorrect SMB header validation. An attacker could exploit this vulnerability by sending a custom SMB file transfer through the targeted device. A successful exploit could cause the device to consume an excessive amount of system memory and prevent the SNORT process from forwarding network traffic. This vulnerability can be exploited using either IPv4 or IPv6 in combination with SMBv2 or SMBv3 network traffic.",Cisco,Cisco Firesight System Software,7.5,HIGH,0.001610000035725534,false,,false,false,false,,,false,false,,2018-10-05T14:29:00.000Z,0 CVE-2018-0453,https://securityvulnerability.io/vulnerability/CVE-2018-0453,Cisco Firepower Management Center and Firepower System Software Sourcefire Tunnel Control Channel Command Execution Vulnerability,"A vulnerability in the Sourcefire tunnel control channel protocol in Cisco Firepower System Software running on Cisco Firepower Threat Defense (FTD) sensors could allow an authenticated, local attacker to execute specific CLI commands with root privileges on the Cisco Firepower Management Center (FMC), or through Cisco FMC on other Firepower sensors and devices that are controlled by the same Cisco FMC. To send the commands, the attacker must have root privileges for at least one affected sensor or the Cisco FMC. The vulnerability exists because the affected software performs insufficient checks for certain CLI commands, if the commands are executed via a Sourcefire tunnel connection. An attacker could exploit this vulnerability by authenticating with root privileges to a Firepower sensor or Cisco FMC, and then sending specific CLI commands to the Cisco FMC or through the Cisco FMC to another Firepower sensor via the Sourcefire tunnel connection. A successful exploit could allow the attacker to modify device configurations or delete files on the device that is running Cisco FMC Software or on any Firepower device that is managed by Cisco FMC.",Cisco,Cisco Firesight System Software,8.2,HIGH,0.0004199999966658652,false,,false,false,false,,,false,false,,2018-10-05T14:29:00.000Z,0 CVE-2017-6735,https://securityvulnerability.io/vulnerability/CVE-2017-6735,,"A vulnerability in the backup and restore functionality of Cisco FireSIGHT System Software could allow an authenticated, local attacker to execute arbitrary code on a targeted system. More Information: CSCvc91092. Known Affected Releases: 6.2.0 6.2.1.",Cisco,Cisco Firesight System Software,6.7,MEDIUM,0.0004199999966658652,false,,false,false,false,,,false,false,,2017-07-10T20:00:00.000Z,0