File Policy Bypass Vulnerability in Cisco Firepower Threat Defense Software
CVE-2024-20261

5.8MEDIUM

Key Information:

Vendor

Cisco

Vendor
CVE Published:
22 May 2024

Badges

๐Ÿ‘พ Exploit Exists

What is CVE-2024-20261?

A vulnerability in the file policy inspection feature of Cisco Firepower Threat Defense Software allows remote attackers to bypass security measures for encrypted archive files. This flaw stems from a logic error that occurs during inspection, which affects specific types of encrypted archives. By exploiting this vulnerability, an attacker can send a specially crafted encrypted archive that should have been blocked, potentially allowing malicious content to be passed through the affected device unimpeded.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

Affected Version(s)

Cisco Firepower Threat Defense Software 6.2.3

Cisco Firepower Threat Defense Software 6.2.3.1

Cisco Firepower Threat Defense Software 6.2.3.2

References

CVSS V3.1

Score:
5.8
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • ๐Ÿ‘พ

    Exploit known to exist

  • Vulnerability published

.