File Policy Bypass Vulnerability in Cisco Firepower Threat Defense Software
CVE-2024-20261
What is CVE-2024-20261?
A vulnerability in the file policy inspection feature of Cisco Firepower Threat Defense Software allows remote attackers to bypass security measures for encrypted archive files. This flaw stems from a logic error that occurs during inspection, which affects specific types of encrypted archives. By exploiting this vulnerability, an attacker can send a specially crafted encrypted archive that should have been blocked, potentially allowing malicious content to be passed through the affected device unimpeded.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Cisco Firepower Threat Defense Software 6.2.3
Cisco Firepower Threat Defense Software 6.2.3.1
Cisco Firepower Threat Defense Software 6.2.3.2
References
CVSS V3.1
Timeline
- ๐พ
Exploit known to exist
Vulnerability published