CVE-2023-20256

Multiple vulnerabilities in the per-user-override feature of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to bypass a configured access control list (ACL) and allow traffic that should be denied to flow through an affected device. These vulnerabilities are due to a logic error that could occur when the affected software constructs and applies per-user-override rules. An attacker could exploit these vulnerabilities by connecting to a network through an affected device that has a vulnerable configuration. A successful exploit could allow the attacker to bypass the interface ACL and access resources that would should be protected.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
5 MEDIUM
NETWORK
LOW
LOW
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:L/A:N
ciscoCNA
5 MEDIUM
NETWORK
LOW
LOW
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:L/A:N
CVEADP
---
---
CISA-ADPADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 6%
VendorProductVersion
ciscoadaptive_security_appliance_software
9.8.4.22
ciscoadaptive_security_appliance_software
9.8.4.25
ciscoadaptive_security_appliance_software
9.8.4.26
ciscoadaptive_security_appliance_software
9.8.4.29
ciscoadaptive_security_appliance_software
9.8.4.32
ciscoadaptive_security_appliance_software
9.8.4.33
ciscoadaptive_security_appliance_software
9.8.4.34
ciscoadaptive_security_appliance_software
9.8.4.35
ciscoadaptive_security_appliance_software
9.8.4.39
ciscoadaptive_security_appliance_software
9.8.4.40
ciscoadaptive_security_appliance_software
9.8.4.41
ciscoadaptive_security_appliance_software
9.8.4.43
ciscoadaptive_security_appliance_software
9.8.4.44
ciscoadaptive_security_appliance_software
9.8.4.45
ciscoadaptive_security_appliance_software
9.8.4.46
ciscoadaptive_security_appliance_software
9.8.4.48
ciscoadaptive_security_appliance_software
9.12.4.2
ciscoadaptive_security_appliance_software
9.12.4.4
ciscoadaptive_security_appliance_software
9.12.4.7
ciscoadaptive_security_appliance_software
9.12.4.8
ciscoadaptive_security_appliance_software
9.12.4.10
ciscoadaptive_security_appliance_software
9.12.4.13
ciscoadaptive_security_appliance_software
9.12.4.18
ciscoadaptive_security_appliance_software
9.12.4.24
ciscoadaptive_security_appliance_software
9.12.4.26
ciscoadaptive_security_appliance_software
9.12.4.29
ciscoadaptive_security_appliance_software
9.12.4.30
ciscoadaptive_security_appliance_software
9.12.4.35
ciscoadaptive_security_appliance_software
9.12.4.37
ciscoadaptive_security_appliance_software
9.12.4.38
ciscoadaptive_security_appliance_software
9.12.4.39
ciscoadaptive_security_appliance_software
9.12.4.40
ciscoadaptive_security_appliance_software
9.12.4.41
ciscoadaptive_security_appliance_software
9.12.4.47
ciscoadaptive_security_appliance_software
9.12.4.48
ciscoadaptive_security_appliance_software
9.12.4.50
ciscoadaptive_security_appliance_software
9.12.4.52
ciscoadaptive_security_appliance_software
9.12.4.54
ciscoadaptive_security_appliance_software
9.12.4.55
ciscoadaptive_security_appliance_software
9.12.4.56
ciscoadaptive_security_appliance_software
9.14.1.10
ciscoadaptive_security_appliance_software
9.14.1.15
ciscoadaptive_security_appliance_software
9.14.1.19
ciscoadaptive_security_appliance_software
9.14.1.30
ciscoadaptive_security_appliance_software
9.14.2
ciscoadaptive_security_appliance_software
9.14.2.4
ciscoadaptive_security_appliance_software
9.14.2.8
ciscoadaptive_security_appliance_software
9.14.2.13
ciscoadaptive_security_appliance_software
9.14.2.15
ciscoadaptive_security_appliance_software
9.14.3
ciscoadaptive_security_appliance_software
9.14.3.1
ciscoadaptive_security_appliance_software
9.14.3.9
ciscoadaptive_security_appliance_software
9.14.3.11
ciscoadaptive_security_appliance_software
9.14.3.13
ciscoadaptive_security_appliance_software
9.14.3.15
ciscoadaptive_security_appliance_software
9.14.3.18
ciscoadaptive_security_appliance_software
9.14.4
ciscoadaptive_security_appliance_software
9.14.4.6
ciscoadaptive_security_appliance_software
9.14.4.7
ciscoadaptive_security_appliance_software
9.14.4.12
ciscoadaptive_security_appliance_software
9.14.4.13
ciscoadaptive_security_appliance_software
9.14.4.14
ciscoadaptive_security_appliance_software
9.14.4.15
ciscoadaptive_security_appliance_software
9.14.4.17
ciscoadaptive_security_appliance_software
9.14.4.22
ciscoadaptive_security_appliance_software
9.14.4.23
ciscoadaptive_security_appliance_software
9.15.1
ciscoadaptive_security_appliance_software
9.15.1.1
ciscoadaptive_security_appliance_software
9.15.1.7
ciscoadaptive_security_appliance_software
9.15.1.10
ciscoadaptive_security_appliance_software
9.15.1.15
ciscoadaptive_security_appliance_software
9.15.1.16
ciscoadaptive_security_appliance_software
9.15.1.17
ciscoadaptive_security_appliance_software
9.15.1.21
ciscoadaptive_security_appliance_software
9.16.1
ciscoadaptive_security_appliance_software
9.16.1.28
ciscoadaptive_security_appliance_software
9.16.2
ciscoadaptive_security_appliance_software
9.16.2.3
ciscoadaptive_security_appliance_software
9.16.2.7
ciscoadaptive_security_appliance_software
9.16.2.11
ciscoadaptive_security_appliance_software
9.16.2.13
ciscoadaptive_security_appliance_software
9.16.2.14
ciscoadaptive_security_appliance_software
9.16.3
ciscoadaptive_security_appliance_software
9.16.3.3
ciscoadaptive_security_appliance_software
9.16.3.14
ciscoadaptive_security_appliance_software
9.16.3.15
ciscoadaptive_security_appliance_software
9.16.3.19
ciscoadaptive_security_appliance_software
9.16.3.23
ciscoadaptive_security_appliance_software
9.16.4
ciscoadaptive_security_appliance_software
9.16.4.9
ciscoadaptive_security_appliance_software
9.16.4.14
ciscoadaptive_security_appliance_software
9.17.1
ciscoadaptive_security_appliance_software
9.17.1.7
ciscoadaptive_security_appliance_software
9.17.1.9
ciscoadaptive_security_appliance_software
9.17.1.10
ciscoadaptive_security_appliance_software
9.17.1.11
ciscoadaptive_security_appliance_software
9.17.1.13
ciscoadaptive_security_appliance_software
9.17.1.15
ciscoadaptive_security_appliance_software
9.17.1.20
ciscoadaptive_security_appliance_software
9.17.1.30
ciscoadaptive_security_appliance_software
9.18.1
ciscoadaptive_security_appliance_software
9.18.1.3
ciscoadaptive_security_appliance_software
9.18.2
ciscoadaptive_security_appliance_software
9.18.2.5
ciscoadaptive_security_appliance_software
9.18.2.7
ciscoadaptive_security_appliance_software
9.18.2.8
ciscoadaptive_security_appliance_software
9.18.3
ciscoadaptive_security_appliance_software
9.19.1
ciscoadaptive_security_appliance_software
9.19.1.5
ciscofirepower_threat_defense
6.2.3.16
ciscofirepower_threat_defense
6.2.3.17
ciscofirepower_threat_defense
6.2.3.18
ciscofirepower_threat_defense
6.4.0.10
ciscofirepower_threat_defense
6.4.0.11
ciscofirepower_threat_defense
6.4.0.12
ciscofirepower_threat_defense
6.4.0.13
ciscofirepower_threat_defense
6.4.0.14
ciscofirepower_threat_defense
6.4.0.15
ciscofirepower_threat_defense
6.4.0.16
ciscofirepower_threat_defense
6.6.1
ciscofirepower_threat_defense
6.6.3
ciscofirepower_threat_defense
6.6.4
ciscofirepower_threat_defense
6.6.5
ciscofirepower_threat_defense
6.6.5.1
ciscofirepower_threat_defense
6.6.5.2
ciscofirepower_threat_defense
6.6.7
ciscofirepower_threat_defense
6.6.7.1
ciscofirepower_threat_defense
6.7.0
ciscofirepower_threat_defense
6.7.0.1
ciscofirepower_threat_defense
6.7.0.2
ciscofirepower_threat_defense
6.7.0.3
ciscofirepower_threat_defense
7.0.0
ciscofirepower_threat_defense
7.0.0.1
ciscofirepower_threat_defense
7.0.1
ciscofirepower_threat_defense
7.0.1.1
ciscofirepower_threat_defense
7.0.2
ciscofirepower_threat_defense
7.0.2.1
ciscofirepower_threat_defense
7.0.3
ciscofirepower_threat_defense
7.0.4
ciscofirepower_threat_defense
7.0.5
ciscofirepower_threat_defense
7.1.0
ciscofirepower_threat_defense
7.1.0.1
ciscofirepower_threat_defense
7.1.0.2
ciscofirepower_threat_defense
7.1.0.3
ciscofirepower_threat_defense
7.2.0
ciscofirepower_threat_defense
7.2.0.1
ciscofirepower_threat_defense
7.2.1
ciscofirepower_threat_defense
7.2.2
ciscofirepower_threat_defense
7.2.3
ciscofirepower_threat_defense
7.3.0
ciscofirepower_threat_defense
7.3.1
ciscofirepower_threat_defense
7.3.1.1
𝑥
= Vulnerable software versions