CVE-2020-3315
5.3
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Exploitability: 3.9 / Impact: 1.4
Source: NVD
Description
Multiple Cisco products are affected by a vulnerability in the Snort detection engine that could allow an unauthenticated, remote attacker to bypass the configured file policies on an affected system. The vulnerability is due to errors in how the Snort detection engine handles specific HTTP responses. An attacker could exploit this vulnerability by sending crafted HTTP packets that would flow through an affected system. A successful exploit could allow the attacker to bypass the configured file policies and deliver a malicious payload to the protected network.
Affected (7)
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Before 6.6.0 | |
| Version 2.9.14.4 |
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| Version 15.2(7)e |
| Running on/with | Platform Versions |
|---|---|
Cisco 1100 4g Integrated Services Router | All versions |
Cisco 1100 6g Integrated Services Router | All versions |
Cisco 1100 Lte Integrated Services Router | All versions |
Cisco 1101 Integrated Services Router | All versions |
Cisco 1109 Integrated Services Router | All versions |
Cisco 1111x Integrated Services Router | All versions |
Cisco 111x Integrated Services Router | All versions |
Cisco 1120 Integrated Services Router | All versions |
Cisco 1160 Integrated Services Router | All versions |
Cisco 4221 Integrated Services Router | All versions |
Cisco 4331 Integrated Services Router | All versions |
Cisco 4431 Integrated Services Router | All versions |
Cisco 4461 Integrated Services Router | All versions |
Cisco Csr1000v | All versions |
Cisco Isa 3000 2c2f K9 | All versions |
Cisco Isa 3000 4c K9 | All versions |
Related CWEs
CWE-668
Exposure of Resource to Wrong Sphere
The product exposes a resource to the wrong control sphere, providing unintended actors with inappropriate access to the resource.
CWE-693
Protection Mechanism Failure
The product does not use or incorrectly uses a protection mechanism that provides sufficient defense against directed attacks against the product.
References (6)
Source: psirt@cisco.com
Source: psirt@cisco.com
Vendor Advisory
Source: psirt@cisco.com
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Timeline
No history available yet.