← Back

CVE-2023-20071

nvd nist
Published: Nov 1, 2023Modified: Jun 17, 2026

JSON object

Loading...
5.8
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:L/A:N
Exploitability: 3.9 / Impact: 1.4
Source: NVD

Description

Multiple Cisco products are affected by a vulnerability in the Snort detection engine that could allow an unauthenticated, remote attacker to bypass the configured policies on an affected system. This vulnerability is due to a flaw in the FTP module of the Snort detection engine. An attacker could exploit this vulnerability by sending crafted FTP traffic through an affected device. A successful exploit could allow the attacker to bypass FTP inspection and deliver a malicious payload.

Affected (14)

4 products
Firepower Threat Defense
Cyber Vision
Unified Threat Defense
Configuration A
4 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Cisco
Before 6.4.0.17
From 6.5.0 to 7.0.6
From 7.1.0 to 7.2.4
From 7.3.0 to 7.3.1.2
Running on/withPlatform Versions
Snort
Snort
Version 2.0
Configuration B
3 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Cisco
From 6.7.0 to 7.0.5
From 7.1.0 to 7.1.0.3
From 7.2.0 to 7.2.1
Running on/withPlatform Versions
Snort
Snort
Before 3.1.32.0
Configuration C
1 vulnerable
Vulnerable SoftwareAffected Versions
Before 4.1.3
Configuration D
5 vulnerable
Vulnerable SoftwareAffected Versions
Cisco
From 17.11 to 17.11.1a
From 17.12 to 17.12.1a
From 17.3 to 17.3.8
From 17.6 to 17.6.6
From 17.9 to 17.9.4
Configuration E
1 vulnerable
Vulnerable SoftwareAffected Versions
All versions

Timeline

No history available yet.