Access Control Bypass Vulnerability in Cisco Products
CVE-2023-20246

5.8MEDIUM

Key Information:

Badges

👾 Exploit Exists

Summary

A vulnerability exists in Cisco's Snort access control policies that can be exploited by an unauthenticated remote attacker. This flaw results from a logic error during the population of access control policies, allowing the attacker to bypass existing rules configured on affected Cisco devices. By establishing a connection to these devices, an attacker could effectively circumvent security measures in place, posing a significant risk to network integrity and data protection.

Affected Version(s)

Cisco Firepower Threat Defense Software 7.0.0

Cisco Firepower Threat Defense Software 7.0.0.1

Cisco Firepower Threat Defense Software 7.0.1

References

CVSS V3.1

Score:
5.8
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • 👾

    Exploit known to exist

  • Vulnerability published

  • Vulnerability Reserved

.