cisco firepower-management-center CVE-2019-1981 vulnerability in Cisco Products
Published on November 5, 2019

Cisco Firepower Threat Defense Software NULL Character Obfuscation Detection Bypass Vulnerability
A vulnerability in the normalization functionality of Cisco Firepower Threat Defense Software, Cisco FirePOWER Services Software for ASA, and Cisco Firepower Management Center Software could allow an unauthenticated, remote attacker to bypass filtering protections. The vulnerability is due to insufficient normalization of a text-based payload. An attacker could exploit this vulnerability by sending traffic that contains specifically obfuscated payloads through an affected device. An exploit could allow the attacker to bypass filtering and deliver malicious payloads to protected systems that would otherwise be blocked.

Vendor Advisory NVD

Weakness Type

Permissions, Privileges, and Access Controls

Weaknesses in this category are related to the management of permissions, privileges, and other security features that are used to perform access control.


Products Associated with CVE-2019-1981

You can be notified by email with stack.watch whenever vulnerabilities like CVE-2019-1981 are published in these products:

 
 
 
 
 

Affected Versions

Cisco Firepower Threat Defense Software:

Exploit Probability

EPSS
0.41%
Percentile
60.51%

EPSS (Exploit Prediction Scoring System) scores estimate the probability that a vulnerability will be exploited in the wild within the next 30 days. The percentile shows you how this score compares to all other vulnerabilities.