← Back

CVE-2023-20215

nvd nist
Published: Aug 3, 2023Modified: Jun 17, 2026

JSON object

Loading...
5.3
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Exploitability: 3.9 / Impact: 1.4
Source: NVD

Description

A vulnerability in the scanning engines of Cisco AsyncOS Software for Cisco Secure Web Appliance could allow an unauthenticated, remote attacker to bypass a configured rule, allowing traffic onto a network that should have been blocked. This vulnerability is due to improper detection of malicious traffic when the traffic is encoded with a specific content format. An attacker could exploit this vulnerability by using an affected device to connect to a malicious server and receiving crafted HTTP responses. A successful exploit could allow the attacker to bypass an explicit block rule and receive traffic that should have been rejected by the device.

Affected (22)

Products: Cisco: Asyncos
1 product
Asyncos
Configuration A
22 vulnerable · 10 platform
Vulnerable SoftwareAffected Versions
Cisco
Version 11.7.0-406
Version 11.7.0-418
Version 11.7.1-006
Version 11.7.1-020
Version 11.7.1-049
Version 11.7.2-011
Version 11.8.0-414
Version 11.8.1-023
Version 11.8.3-018
Version 11.8.3-021
Version 12.0.1-268
Version 12.0.3-007
Version 12.5.1-011
Version 12.5.2-007
Version 12.5.4-005
Version 12.5.5-004
Version 14.0.2-012
Version 14.0.3-014
Version 14.0.4-005
Version 14.5.0-498
Version 14.5.1-008
Version 14.5.1-016
Running on/withPlatform Versions
Cisco
S195
All versions
Cisco
S395
All versions
Cisco
S695
All versions
Cisco
Web Security Appliance S170
All versions
Cisco
Web Security Appliance S190
All versions
Cisco
Web Security Appliance S380
All versions
Cisco
Web Security Appliance S390
All versions
Cisco
Web Security Appliance S680
All versions
Cisco
Web Security Appliance S690
All versions
Cisco
Web Security Appliance S690x
All versions

Timeline

No history available yet.