IT

Tracker / CVE-2023-20071

CVE-2023-20071

Medium 5.8

Multiple Cisco products are affected by a vulnerability in the Snort detection engine that could allow an unauthenticated, remote attacker to bypass the configured policies on an affected system. This vulnerability is due to a flaw in the FTP module of the Snort detection engine. An attacker could exploit this vulnerability by sending crafted FTP traffic through an affected device. A successful exploit could allow the attacker to bypass FTP inspection and deliver a malicious payload.

Affected products and versions

cisco cyber_vision · … → 4.1.3
cisco meraki_mx_security_appliance_firmware
cisco secure_firewall_threat_defense · … → 6.4.0.17
cisco secure_firewall_threat_defense · 6.5.0 → 7.0.6
cisco secure_firewall_threat_defense · 6.7.0 → 7.0.5
cisco secure_firewall_threat_defense · 7.1.0 → 7.1.0.3
cisco secure_firewall_threat_defense · 7.1.0 → 7.2.4
cisco secure_firewall_threat_defense · 7.2.0 → 7.2.1
cisco secure_firewall_threat_defense · 7.3.0 → 7.3.1.2
cisco unified_threat_defense · 17.11 → 17.11.1a
cisco unified_threat_defense · 17.12 → 17.12.1a
cisco unified_threat_defense · 17.3 → 17.3.8
cisco unified_threat_defense · 17.6 → 17.6.6
cisco unified_threat_defense · 17.9 → 17.9.4

Analysis

This page is not indexable yet.Until it carries original analysis — what it actually exposes, how to check in two minutes whether a system was touched, what to do if it was — the page stays noindex. The database decides that, not the template.

References