Vulnerabilities > Cisco > Firepower Extensible Operating System > 2.2.1.58

DATE CVE VULNERABILITY TITLE RISK
2017-11-16 CVE-2017-12299 Improper Input Validation vulnerability in Cisco Firepower Extensible Operating System 2.2(1.58)
A vulnerability exists in the process of creating default IP blocks during device initialization for Cisco ASA Next-Generation Firewall Services that could allow an unauthenticated, remote attacker to send traffic to the local IP address of the device, bypassing any filters that are configured to deny local IP management traffic.
network
low complexity
cisco CWE-20
5.3
2017-10-19 CVE-2017-3883 Allocation of Resources Without Limits or Throttling vulnerability in Cisco Firepower Extensible Operating System
A vulnerability in the authentication, authorization, and accounting (AAA) implementation of Cisco Firepower Extensible Operating System (FXOS) and NX-OS System Software could allow an unauthenticated, remote attacker to cause an affected device to reload.
network
low complexity
cisco CWE-770
8.6