CVE-2017-12300 (CNNVD-201711-678)
中文标题:
Cisco Firepower System Software SNORT检测引擎安全漏洞
英文标题:
A vulnerability in the SNORT detection engine of Cisco Firepower System Software could allow an unau...
漏洞描述
中文描述:
Cisco Firepower System Software是美国思科(Cisco)公司的一款下一代防火墙产品(NGFW)。SNORT detection engine是其中的一个入侵检测引擎。 Cisco Firepower System Software中的SNORT检测引擎存在安全漏洞,该漏洞源于程序没有正确的检测SMB2文件。远程攻击者可通过发送特制的SMB2转换请求利用该漏洞绕过过滤器。
英文描述:
A vulnerability in the SNORT detection engine of Cisco Firepower System Software could allow an unauthenticated, remote attacker to bypass a file policy that is configured to block the Server Message Block Version 2 (SMB2) protocol. The vulnerability is due to the incorrect detection of an SMB2 file when the detection is based on the length of the file. An attacker could exploit this vulnerability by sending a crafted SMB2 transfer request through the targeted device. A successful exploit could allow the attacker to bypass filters that are configured to block SMB2 traffic. Cisco Bug IDs: CSCve58398.
CWE类型:
标签:
受影响产品
| 厂商 | 产品 | 版本 | 版本范围 | 平台 | CPE |
|---|---|---|---|---|---|
| cisco | secure_firewall_management_center | 2.9.9 | - | - |
cpe:2.3:a:cisco:secure_firewall_management_center:2.9.9:*:*:*:*:*:*:*
|
| cisco | secure_firewall_management_center | 2.9.10 | - | - |
cpe:2.3:a:cisco:secure_firewall_management_center:2.9.10:*:*:*:*:*:*:*
|
| cisco | secure_firewall_management_center | 2.9.11 | - | - |
cpe:2.3:a:cisco:secure_firewall_management_center:2.9.11:*:*:*:*:*:*:*
|
| cisco | secure_firewall_management_center | 2.9.12 | - | - |
cpe:2.3:a:cisco:secure_firewall_management_center:2.9.12:*:*:*:*:*:*:*
|
解决方案
中文解决方案:
英文解决方案:
临时解决方案:
CVSS评分详情
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:L/A:N
时间信息
利用信息
数据源详情
| 数据源 | 记录ID | 版本 | 提取时间 |
|---|---|---|---|
| CVE | cve_CVE-2017-12300 |
2025-11-11 15:19:17 | 2025-11-11 07:34:33 |
| NVD | nvd_CVE-2017-12300 |
2025-11-11 14:55:33 | 2025-11-11 07:43:12 |
| CNNVD | cnnvd_CNNVD-201711-678 |
2025-11-11 15:09:55 | 2025-11-11 07:53:25 |
版本与语言
安全公告
变更历史
查看详细变更
- vulnerability_type: 未提取 -> 输入验证错误
- cnnvd_id: 未提取 -> CNNVD-201711-678
- data_sources: ['cve', 'nvd'] -> ['cnnvd', 'cve', 'nvd']
查看详细变更
- cvss_score: 未提取 -> 5.8
- cvss_vector: NOT_EXTRACTED -> CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:L/A:N
- cvss_version: NOT_EXTRACTED -> 3.0
- affected_products_count: 0 -> 4
- data_sources: ['cve'] -> ['cve', 'nvd']