CVE-2019-1695 (CNNVD-201905-027)
中文标题:
Cisco Firepower Threat Defense 安全漏洞
英文标题:
Cisco Adaptive Security Appliance and Firepower Threat Defense Software Layer 2 Filtering Bypass Vulnerability
漏洞描述
中文描述:
Cisco Firepower Threat Defense(FTD)是美国思科(Cisco)公司的一套提供下一代防火墙服务的统一软件。 Cisco Firepower 2100 Series中的ASA Software和FTD Software的检测引擎存在安全漏洞。该漏洞源于网络系统或产品未正确限制来自未授权角色的资源访问。
英文描述:
A vulnerability in the detection engine of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, adjacent attacker to send data directly to the kernel of an affected device. The vulnerability exists because the software improperly filters Ethernet frames sent to an affected device. An attacker could exploit this vulnerability by sending crafted packets to the management interface of an affected device. A successful exploit could allow the attacker to bypass the Layer 2 (L2) filters and send data directly to the kernel of the affected device. A malicious frame successfully delivered would make the target device generate a specific syslog entry.
CWE类型:
标签:
受影响产品
| 厂商 | 产品 | 版本 | 版本范围 | 平台 | CPE |
|---|---|---|---|---|---|
| Cisco | Cisco Adaptive Security Appliance (ASA) Software | - | < 9.8.4 | - |
cpe:2.3:a:cisco:cisco_adaptive_security_appliance_(asa)_software:*:*:*:*:*:*:*:*
|
| Cisco | Cisco Firepower Threat Defense (FTD) Software | - | < 6.2.3.12 | - |
cpe:2.3:a:cisco:cisco_firepower_threat_defense_(ftd)_software:*:*:*:*:*:*:*:*
|
| cisco | adaptive_security_appliance_software | * | - | - |
cpe:2.3:a:cisco:adaptive_security_appliance_software:*:*:*:*:*:*:*:*
|
| cisco | firepower_threat_defense | * | - | - |
cpe:2.3:a:cisco:firepower_threat_defense:*:*:*:*:*:*:*:*
|
解决方案
中文解决方案:
英文解决方案:
临时解决方案:
CVSS评分详情
3.0 (cna)
MEDIUMCVSS:3.0/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
时间信息
利用信息
数据源详情
| 数据源 | 记录ID | 版本 | 提取时间 |
|---|---|---|---|
| CVE | cve_CVE-2019-1695 |
2025-11-11 15:20:08 | 2025-11-11 07:35:38 |
| NVD | nvd_CVE-2019-1695 |
2025-11-11 14:56:22 | 2025-11-11 07:44:09 |
| CNNVD | cnnvd_CNNVD-201905-027 |
2025-11-11 15:10:12 | 2025-11-11 07:54:29 |
版本与语言
安全公告
变更历史
查看详细变更
- vulnerability_type: 未提取 -> 其他
- cnnvd_id: 未提取 -> CNNVD-201905-027
- data_sources: ['cve', 'nvd'] -> ['cnnvd', 'cve', 'nvd']
查看详细变更
- affected_products_count: 5 -> 4
- data_sources: ['cve'] -> ['cve', 'nvd']