CVE-2023-20071CWE-1039

CVE-2023-20071

Medium · published November 1, 2023

CVSS v3.1
5.8
EPSS
1%
Percentile
42.2
In the wild
Unconfirmed
What it is

Multiple Cisco products are affected by a vulnerability in the Snort detection engine that could allow an unauthenticated, remote attacker to bypass the configured policies on an affected system. This vulnerability is due to a flaw in the FTP module of the Snort detection engine. An attacker could exploit this vulnerability by sending crafted FTP traffic through an affected device. A successful exploit could allow the attacker to bypass FTP inspection and deliver a malicious payload.

The record
Technical detail
CVSS v3.1
5.8 · MEDIUM
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:L/A:N
CVSS v4.0
Not supplied
EPSS
0.00519 · 42.2th percentile
Weakness
CWE-1039 · Inadequate Detection or Handling of Adversarial Input Perturbations in Automated Recognition Mechanism
Published
2023-11-01T22:15Z
Affected products (14)
ProductVersionsFixed in
cisco/secure_firewall_threat_defense< 6.4.0.176.4.0.17
cisco/secure_firewall_threat_defense≥ 6.5.0, < 7.0.67.0.6
cisco/secure_firewall_threat_defense≥ 7.1.0, < 7.2.47.2.4
cisco/secure_firewall_threat_defense≥ 7.3.0, < 7.3.1.27.3.1.2
cisco/secure_firewall_threat_defense≥ 6.7.0, < 7.0.57.0.5
cisco/secure_firewall_threat_defense≥ 7.1.0, < 7.1.0.37.1.0.3
cisco/secure_firewall_threat_defense≥ 7.2.0, < 7.2.17.2.1
cisco/cyber_vision< 4.1.34.1.3
cisco/unified_threat_defense≥ 17.3, < 17.3.817.3.8
cisco/unified_threat_defense≥ 17.6, < 17.6.617.6.6
cisco/unified_threat_defense≥ 17.9, < 17.9.417.9.4
cisco/unified_threat_defense≥ 17.11, < 17.11.1a17.11.1a
cisco/unified_threat_defense≥ 17.12, < 17.12.1a17.12.1a
cisco/meraki_mx_security_appliance_firmwareall versions
References (2)
EPSS history
Timeline
  • 01 NOV 17:07Z
    Multiple Cisco products are affected by a vulnerability in the Snort detection engine that could allow an unauthenticated, remote attacker to bypass the…
    cvelistv5