CVE-2023-20071
01.11.2023, 18:15
Multiple Cisco products are affected by a vulnerability in the Snort detection engine that could allow an unauthenticated, remote attacker to bypass the configured policies on an affected system. This vulnerability is due to a flaw in the FTP module of the Snort detection engine. An attacker could exploit this vulnerability by sending crafted FTP traffic through an affected device. A successful exploit could allow the attacker to bypass FTP inspection and deliver a malicious payload.Enginsight
Vendor | Product | Version |
---|---|---|
cisco | firepower_threat_defense | 𝑥 < 6.4.0.17 |
cisco | firepower_threat_defense | 6.5.0 ≤ 𝑥 < 7.0.6 |
cisco | firepower_threat_defense | 7.1.0 ≤ 𝑥 < 7.2.4 |
cisco | firepower_threat_defense | 7.3.0 ≤ 𝑥 < 7.3.1.2 |
cisco | firepower_threat_defense | 6.7.0 ≤ 𝑥 < 7.0.5 |
cisco | firepower_threat_defense | 7.1.0 ≤ 𝑥 < 7.1.0.3 |
cisco | firepower_threat_defense | 7.2.0 ≤ 𝑥 < 7.2.1 |
cisco | cyber_vision | 𝑥 < 4.1.3 |
cisco | unified_threat_defense | 17.3 ≤ 𝑥 < 17.3.8 |
cisco | unified_threat_defense | 17.6 ≤ 𝑥 < 17.6.6 |
cisco | unified_threat_defense | 17.9 ≤ 𝑥 < 17.9.4 |
cisco | unified_threat_defense | 17.11 ≤ 𝑥 < 17.11.1a |
cisco | unified_threat_defense | 17.12 ≤ 𝑥 < 17.12.1a |
cisco | meraki_mx_security_appliance_firmware | - |
𝑥
= Vulnerable software versions