CVE-2024-20384

A vulnerability in the Network Service Group (NSG) feature of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to bypass a configured access control list (ACL) and allow traffic that should be denied to flow through an affected device.

 This vulnerability is due to a logic error that occurs when NSG ACLs are populated on an affected device. An attacker could exploit this vulnerability by establishing a connection to the affected device. A successful exploit could allow the attacker to bypass configured ACL rules.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
5.8 MEDIUM
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:L/A:N
ciscoCNA
5.8 MEDIUM
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:L/A:N
CISA-ADPADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 29%
VendorProductVersion
ciscoadaptive_security_appliance_software
9.16.1
ciscoadaptive_security_appliance_software
9.16.1.28
ciscoadaptive_security_appliance_software
9.16.2
ciscoadaptive_security_appliance_software
9.16.2.3
ciscoadaptive_security_appliance_software
9.16.2.7
ciscoadaptive_security_appliance_software
9.16.2.11
ciscoadaptive_security_appliance_software
9.16.2.13
ciscoadaptive_security_appliance_software
9.16.2.14
ciscoadaptive_security_appliance_software
9.16.3
ciscoadaptive_security_appliance_software
9.16.3.3
ciscoadaptive_security_appliance_software
9.16.3.14
ciscoadaptive_security_appliance_software
9.16.3.15
ciscoadaptive_security_appliance_software
9.16.3.19
ciscoadaptive_security_appliance_software
9.16.3.23
ciscoadaptive_security_appliance_software
9.16.4
ciscoadaptive_security_appliance_software
9.16.4.9
ciscoadaptive_security_appliance_software
9.16.4.14
ciscoadaptive_security_appliance_software
9.16.4.18
ciscoadaptive_security_appliance_software
9.16.4.19
ciscoadaptive_security_appliance_software
9.16.4.27
ciscoadaptive_security_appliance_software
9.16.4.38
ciscoadaptive_security_appliance_software
9.16.4.39
ciscoadaptive_security_appliance_software
9.16.4.42
ciscoadaptive_security_appliance_software
9.16.4.48
ciscoadaptive_security_appliance_software
9.16.4.55
ciscoadaptive_security_appliance_software
9.16.4.57
ciscoadaptive_security_appliance_software
9.16.4.61
ciscoadaptive_security_appliance_software
9.17.1
ciscoadaptive_security_appliance_software
9.17.1.7
ciscoadaptive_security_appliance_software
9.17.1.9
ciscoadaptive_security_appliance_software
9.17.1.10
ciscoadaptive_security_appliance_software
9.17.1.11
ciscoadaptive_security_appliance_software
9.17.1.13
ciscoadaptive_security_appliance_software
9.17.1.15
ciscoadaptive_security_appliance_software
9.17.1.20
ciscoadaptive_security_appliance_software
9.17.1.30
ciscoadaptive_security_appliance_software
9.17.1.33
ciscoadaptive_security_appliance_software
9.17.1.39
ciscoadaptive_security_appliance_software
9.18.1
ciscoadaptive_security_appliance_software
9.18.1.3
ciscoadaptive_security_appliance_software
9.18.2
ciscoadaptive_security_appliance_software
9.18.2.5
ciscoadaptive_security_appliance_software
9.18.2.7
ciscoadaptive_security_appliance_software
9.18.2.8
ciscoadaptive_security_appliance_software
9.18.3
ciscoadaptive_security_appliance_software
9.18.3.39
ciscoadaptive_security_appliance_software
9.18.3.46
ciscoadaptive_security_appliance_software
9.18.3.53
ciscoadaptive_security_appliance_software
9.18.3.55
ciscoadaptive_security_appliance_software
9.18.3.56
ciscoadaptive_security_appliance_software
9.18.4
ciscoadaptive_security_appliance_software
9.18.4.5
ciscoadaptive_security_appliance_software
9.18.4.8
ciscoadaptive_security_appliance_software
9.18.4.22
ciscoadaptive_security_appliance_software
9.18.4.24
ciscoadaptive_security_appliance_software
9.18.4.29
ciscoadaptive_security_appliance_software
9.19.1
ciscoadaptive_security_appliance_software
9.19.1.5
ciscoadaptive_security_appliance_software
9.19.1.9
ciscoadaptive_security_appliance_software
9.19.1.12
ciscoadaptive_security_appliance_software
9.19.1.18
ciscoadaptive_security_appliance_software
9.19.1.22
ciscoadaptive_security_appliance_software
9.19.1.24
ciscoadaptive_security_appliance_software
9.19.1.27
ciscoadaptive_security_appliance_software
9.19.1.28
ciscoadaptive_security_appliance_software
9.19.1.31
ciscoadaptive_security_appliance_software
9.20.1
ciscoadaptive_security_appliance_software
9.20.1.5
ciscoadaptive_security_appliance_software
9.20.2
ciscoadaptive_security_appliance_software
9.20.2.10
ciscoadaptive_security_appliance_software
9.20.2.21
ciscoadaptive_security_appliance_software
9.20.2.22
ciscofirepower_threat_defense
7.0.0
ciscofirepower_threat_defense
7.0.0.1
ciscofirepower_threat_defense
7.0.1
ciscofirepower_threat_defense
7.0.1.1
ciscofirepower_threat_defense
7.0.2
ciscofirepower_threat_defense
7.0.2.1
ciscofirepower_threat_defense
7.0.3
ciscofirepower_threat_defense
7.0.4
ciscofirepower_threat_defense
7.0.5
ciscofirepower_threat_defense
7.0.6
ciscofirepower_threat_defense
7.0.6.1
ciscofirepower_threat_defense
7.0.6.2
ciscofirepower_threat_defense
7.1.0
ciscofirepower_threat_defense
7.1.0.1
ciscofirepower_threat_defense
7.1.0.2
ciscofirepower_threat_defense
7.1.0.3
ciscofirepower_threat_defense
7.2.0
ciscofirepower_threat_defense
7.2.0.1
ciscofirepower_threat_defense
7.2.1
ciscofirepower_threat_defense
7.2.2
ciscofirepower_threat_defense
7.2.3
ciscofirepower_threat_defense
7.2.4
ciscofirepower_threat_defense
7.2.4.1
ciscofirepower_threat_defense
7.2.5
ciscofirepower_threat_defense
7.2.5.1
ciscofirepower_threat_defense
7.2.5.2
ciscofirepower_threat_defense
7.2.6
ciscofirepower_threat_defense
7.2.7
ciscofirepower_threat_defense
7.2.8
ciscofirepower_threat_defense
7.2.8.1
ciscofirepower_threat_defense
7.3.0
ciscofirepower_threat_defense
7.3.1
ciscofirepower_threat_defense
7.3.1.1
ciscofirepower_threat_defense
7.3.1.2
ciscofirepower_threat_defense
7.4.0
ciscofirepower_threat_defense
7.4.1
ciscofirepower_threat_defense
7.4.1.1
ciscofirepower_threat_defense
7.4.2
𝑥
= Vulnerable software versions