Tracker / CVE-2023-20071
CVE-2023-20071
Medium 5.8
Multiple Cisco products are affected by a vulnerability in the Snort detection engine that could allow an unauthenticated, remote attacker to bypass the configured policies on an affected system. This vulnerability is due to a flaw in the FTP module of the Snort detection engine. An attacker could exploit this vulnerability by sending crafted FTP traffic through an affected device. A successful exploit could allow the attacker to bypass FTP inspection and deliver a malicious payload.
Affected products and versions
| cisco | cyber_vision · … → 4.1.3 |
|---|---|
| cisco | meraki_mx_security_appliance_firmware |
| cisco | secure_firewall_threat_defense · … → 6.4.0.17 |
| cisco | secure_firewall_threat_defense · 6.5.0 → 7.0.6 |
| cisco | secure_firewall_threat_defense · 6.7.0 → 7.0.5 |
| cisco | secure_firewall_threat_defense · 7.1.0 → 7.1.0.3 |
| cisco | secure_firewall_threat_defense · 7.1.0 → 7.2.4 |
| cisco | secure_firewall_threat_defense · 7.2.0 → 7.2.1 |
| cisco | secure_firewall_threat_defense · 7.3.0 → 7.3.1.2 |
| cisco | unified_threat_defense · 17.11 → 17.11.1a |
| cisco | unified_threat_defense · 17.12 → 17.12.1a |
| cisco | unified_threat_defense · 17.3 → 17.3.8 |
| cisco | unified_threat_defense · 17.6 → 17.6.6 |
| cisco | unified_threat_defense · 17.9 → 17.9.4 |
Analysis
This page is not indexable yet.Until it carries original analysis — what it actually exposes, how to check in two minutes whether a system was touched, what to do if it was — the page stays noindex. The database decides that, not the template.