← Back

CVE-2020-3315

nvd nist
Published: May 6, 2020Modified: Jun 17, 2026

JSON object

Loading...
5.3
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Exploitability: 3.9 / Impact: 1.4
Source: NVD

Description

Multiple Cisco products are affected by a vulnerability in the Snort detection engine that could allow an unauthenticated, remote attacker to bypass the configured file policies on an affected system. The vulnerability is due to errors in how the Snort detection engine handles specific HTTP responses. An attacker could exploit this vulnerability by sending crafted HTTP packets that would flow through an affected system. A successful exploit could allow the attacker to bypass the configured file policies and deliver a malicious payload to the protected network.

Affected (7)

3 products
Firepower Threat Defense
Secure Firewall Management Center
Ios
Configuration A
4 vulnerable
Vulnerable SoftwareAffected Versions
Before 6.6.0
Cisco
Version 2.9.14.4
Version 2.9.15
Version 2.9.16
Configuration B
3 vulnerable · 16 platform
Vulnerable SoftwareAffected Versions
Cisco
Version 15.2(7)e
Version 16.11.2
Version 17.3.1
Running on/withPlatform Versions
Cisco
1100 4g Integrated Services Router
All versions
Cisco
1100 6g Integrated Services Router
All versions
Cisco
1100 Lte Integrated Services Router
All versions
Cisco
1101 Integrated Services Router
All versions
Cisco
1109 Integrated Services Router
All versions
Cisco
1111x Integrated Services Router
All versions
Cisco
111x Integrated Services Router
All versions
Cisco
1120 Integrated Services Router
All versions
Cisco
1160 Integrated Services Router
All versions
Cisco
4221 Integrated Services Router
All versions
Cisco
4331 Integrated Services Router
All versions
Cisco
4431 Integrated Services Router
All versions
Cisco
4461 Integrated Services Router
All versions
Cisco
Csr1000v
All versions
Cisco
Isa 3000 2c2f K9
All versions
Cisco
Isa 3000 4c K9
All versions

Timeline

No history available yet.