Unauthorized Access to Network Policies Through TCP Intercept and Snort 3 Vulnerability
Key Information
- Vendor
- Cisco
- Status
- Cisco Firepower Threat Defense Software
- Vendor
- CVE Published:
- 23 October 2024
Badges
Summary
A vulnerability in the interaction between the TCP Intercept feature and the Snort 3 detection engine on Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to bypass configured policies on an affected system. Devices that are configured with Snort 2 are not affected by this vulnerability. This vulnerability is due to a logic error when handling embryonic (half-open) TCP connections. An attacker could exploit this vulnerability by sending a crafted traffic pattern through an affected device. A successful exploit could allow unintended traffic to enter the network protected by the affected device.
Affected Version(s)
Cisco Firepower Threat Defense Software = 6.2.3
Cisco Firepower Threat Defense Software = 6.2.3.1
Cisco Firepower Threat Defense Software = 6.2.3.2
CVSS V3.1
Timeline
- 👾
Exploit exists.
Risk change from: null to: 5.8 - (MEDIUM)
Vulnerability published.