Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2023-20267

Опубликовано: 01 нояб. 2023
Источник: nvd
CVSS3: 4
CVSS3: 5.3
EPSS Низкий

Описание

A vulnerability in the IP geolocation rules of Snort 3 could allow an unauthenticated, remote attacker to potentially bypass IP address restrictions. This vulnerability exists because the configuration for IP geolocation rules is not parsed properly. An attacker could exploit this vulnerability by spoofing an IP address until they bypass the restriction. A successful exploit could allow the attacker to bypass location-based IP address restrictions.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:cisco:firepower_threat_defense:*:*:*:*:*:*:*:*
Версия от 6.7.0 (включая) до 7.3.1.1 (включая)

EPSS

Процентиль: 1%
0.00011
Низкий

4 Medium

CVSS3

5.3 Medium

CVSS3

Дефекты

CWE-284
NVD-CWE-noinfo

Связанные уязвимости

CVSS3: 4
github
больше 2 лет назад

A vulnerability in the IP geolocation rules of Snort 3 could allow an unauthenticated, remote attacker to potentially bypass IP address restrictions. This vulnerability exists because the configuration for IP geolocation rules is not parsed properly. An attacker could exploit this vulnerability by spoofing an IP address until they bypass the restriction. A successful exploit could allow the attacker to bypass location-based IP address restrictions.

EPSS

Процентиль: 1%
0.00011
Низкий

4 Medium

CVSS3

5.3 Medium

CVSS3

Дефекты

CWE-284
NVD-CWE-noinfo