Access Control Bypass Vulnerability in Cisco Products
CVE-2023-20246
5.8MEDIUM
Summary
A vulnerability exists in Cisco's Snort access control policies that can be exploited by an unauthenticated remote attacker. This flaw results from a logic error during the population of access control policies, allowing the attacker to bypass existing rules configured on affected Cisco devices. By establishing a connection to these devices, an attacker could effectively circumvent security measures in place, posing a significant risk to network integrity and data protection.
Affected Version(s)
Cisco Firepower Threat Defense Software 7.0.0
Cisco Firepower Threat Defense Software 7.0.0.1
Cisco Firepower Threat Defense Software 7.0.1
References
CVSS V3.1
Score:
5.8
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed
Timeline
- 👾
Exploit known to exist
Vulnerability published
Vulnerability Reserved