← Back

CVE-2024-20407

nvd nist
Published: Oct 23, 2024Modified: Aug 5, 2025

JSON object

Loading...
5.8
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:L/A:N
Exploitability: 3.9 / Impact: 1.4
Source: psirt@cisco.com (Secondary)

Description

A vulnerability in the interaction between the TCP Intercept feature and the Snort 3 detection engine on Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to bypass configured policies on an affected system. Devices that are configured with Snort 2 are not affected by this vulnerability. This vulnerability is due to a logic error when handling embryonic (half-open) TCP connections. An attacker could exploit this vulnerability by sending a crafted traffic pattern through an affected device. A successful exploit could allow unintended traffic to enter the network protected by the affected device.

Affected (90)

1 product
Firepower Threat Defense
Configuration A
90 vulnerable
Vulnerable SoftwareAffected Versions
Cisco
Version 6.2.3.10
Version 6.2.3.11
Version 6.2.3.12
Version 6.2.3.13
Version 6.2.3.14
Version 6.2.3.15
Version 6.2.3.16
Version 6.2.3.17
Version 6.2.3.18
Version 6.2.3.1
Version 6.2.3.2
Version 6.2.3.3
Version 6.2.3.4
Version 6.2.3.5
Version 6.2.3.6
Version 6.2.3.7
Version 6.2.3.8
Version 6.2.3.9
Version 6.2.3
Version 6.4.0.10
Version 6.4.0.11
Version 6.4.0.12
Version 6.4.0.13
Version 6.4.0.14
Version 6.4.0.15
Version 6.4.0.16
Version 6.4.0.17
Version 6.4.0.18
Version 6.4.0.1
Version 6.4.0.2
Version 6.4.0.3
Version 6.4.0.4
Version 6.4.0.5
Version 6.4.0.6
Version 6.4.0.7
Version 6.4.0.8
Version 6.4.0.9
Version 6.4.0
Version 6.6.0.1
Version 6.6.0
Version 6.6.1
Version 6.6.3
Version 6.6.4
Version 6.6.5.1
Version 6.6.5.2
Version 6.6.5
Version 6.6.7.1
Version 6.6.7.2
Version 6.6.7
Version 6.7.0.1
Version 6.7.0.2
Version 6.7.0.3
Version 6.7.0
Version 7.0.0.1
Version 7.0.0
Version 7.0.1.1
Version 7.0.1
Version 7.0.2.1
Version 7.0.2
Version 7.0.3
Version 7.0.4
Version 7.0.5
Version 7.0.6.1
Version 7.0.6.2
Version 7.0.6
Version 7.1.0.1
Version 7.1.0.2
Version 7.1.0.3
Version 7.1.0
Version 7.2.0.1
Version 7.2.0
Version 7.2.1
Version 7.2.2
Version 7.2.3
Version 7.2.4.1
Version 7.2.4
Version 7.2.5.1
Version 7.2.5.2
Version 7.2.5
Version 7.2.6
Version 7.2.7
Version 7.2.8.1
Version 7.2.8
Version 7.3.0
Version 7.3.1.1
Version 7.3.1.2
Version 7.3.1
Version 7.4.0
Version 7.4.1.1
Version 7.4.1

Related CWEs

Timeline

No history available yet.