Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2024-20342

Опубликовано: 23 окт. 2024
Источник: nvd
CVSS3: 5.8
CVSS3: 8.6
EPSS Низкий

Описание

Multiple Cisco products are affected by a vulnerability in the rate filtering feature of the Snort detection engine that could allow an unauthenticated, remote attacker to bypass a configured rate limiting filter. 

This vulnerability is due to an incorrect connection count comparison. An attacker could exploit this vulnerability by sending traffic through an affected device at a rate that exceeds a configured rate filter. A successful exploit could allow the attacker to successfully bypass the rate filter. This could allow unintended traffic to enter the network protected by the affected device.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:cisco:snort:*:*:*:*:*:*:*:*
Версия от 3.0.0.0 (включая) до 3.1.74.0 (исключая)
Конфигурация 2

Одно из

cpe:2.3:a:cisco:firepower_threat_defense_software:*:*:*:*:*:*:*:*
Версия до 7.0.6.2 (исключая)
cpe:2.3:a:cisco:firepower_threat_defense_software:*:*:*:*:*:*:*:*
Версия от 7.2.0 (включая) до 7.2.6 (исключая)
cpe:2.3:a:cisco:firepower_threat_defense_software:*:*:*:*:*:*:*:*
Версия от 7.4.0 (включая) до 7.4.2 (исключая)
cpe:2.3:a:cisco:firepower_threat_defense_software:7.1.0:*:*:*:*:*:*:*
cpe:2.3:a:cisco:firepower_threat_defense_software:7.3.0:*:*:*:*:*:*:*

EPSS

Процентиль: 11%
0.00037
Низкий

5.8 Medium

CVSS3

8.6 High

CVSS3

Дефекты

CWE-1025

Связанные уязвимости

CVSS3: 5.8
github
больше 1 года назад

Multiple Cisco products are affected by a vulnerability in the rate filtering feature of the Snort detection engine that could allow an unauthenticated, remote attacker to bypass a configured rate limiting filter. This vulnerability is due to an incorrect connection count comparison. An attacker could exploit this vulnerability by sending traffic through an affected device at a rate that exceeds a configured rate filter. A successful exploit could allow the attacker to successfully bypass the rate filter. This could allow unintended traffic to enter the network protected by the affected device.

CVSS3: 5.8
fstec
больше 1 года назад

Уязвимость модуля Snort микропрограммного обеспечения межсетевых экранов Cisco Firepower Threat Defense (FTD), позволяющая нарушителю обойти существующие ограничения безопасности

EPSS

Процентиль: 11%
0.00037
Низкий

5.8 Medium

CVSS3

8.6 High

CVSS3

Дефекты

CWE-1025