Vulnerability in Snort Detection Engine Affects Cisco Products
CVE-2023-20071
5.8MEDIUM
Key Information:
- Vendor
Cisco
- Status
- Vendor
- CVE Published:
- 1 November 2023
What is CVE-2023-20071?
A vulnerability exists within the FTP module of Cisco's Snort detection engine, which enables unauthenticated, remote attackers to potentially bypass established security policies on affected systems. By sending specifically crafted FTP traffic, attackers can exploit this flaw to evade FTP inspections and potentially deliver malicious payloads. This poses a significant risk to network integrity, allowing unauthorized access and potentially harmful activities.
Affected Version(s)
Cisco Cyber Vision 3.0.4
Cisco Cyber Vision 3.0.0
Cisco Cyber Vision 3.0.1