A vulnerability in the application policy configuration of the Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to gain unauthorized read access to sensitive data. The vulnerability is due to insufficient application identification. An attacker could exploit this vulnerability by sending crafted traffic to an affected device. A successful exploit could allow the attacker to gain unauthorized read access to sensitive data.

Project Subscriptions

Vendors Products
Amp 7150 Subscribe
Amp 8150 Subscribe
Firepower 7010 Subscribe
Firepower 7020 Subscribe
Firepower 7030 Subscribe
Firepower 7050 Subscribe
Firepower 7110 Subscribe
Firepower 7115 Subscribe
Firepower 7120 Subscribe
Firepower 7125 Subscribe
Firepower 8120 Subscribe
Firepower 8130 Subscribe
Firepower 8140 Subscribe
Firepower 8250 Subscribe
Firepower 8260 Subscribe
Firepower 8270 Subscribe
Firepower 8290 Subscribe
Firepower 8350 Subscribe
Firepower 8360 Subscribe
Firepower 8370 Subscribe
Firepower 8390 Subscribe
Firepower Management Center 1000 Subscribe
Firepower Management Center 2000 Subscribe
Firepower Management Center 2500 Subscribe
Firepower Management Center 4000 Subscribe
Firepower Threat Defense Subscribe
Firesight Management Center 1500 Subscribe
Firesight Management Center 3500 Subscribe
Firesight Management Center 750 Subscribe
Advisories
Source ID Title
EUVD EUVD EUVD-2019-4218 A vulnerability in the application policy configuration of the Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to gain unauthorized read access to sensitive data. The vulnerability is due to insufficient application identification. An attacker could exploit this vulnerability by sending crafted traffic to an affected device. A successful exploit could allow the attacker to gain unauthorized read access to sensitive data.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Tue, 19 Nov 2024 19:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: cisco

Published:

Updated: 2024-11-19T19:00:54.288Z

Reserved: 2019-06-04T00:00:00

Link: CVE-2019-12627

cve-icon Vulnrichment

Updated: 2024-08-04T23:24:39.109Z

cve-icon NVD

Status : Modified

Published: 2019-08-21T19:15:13.293

Modified: 2024-11-21T04:23:13.203

Link: CVE-2019-12627

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses