Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2024-20363

Опубликовано: 22 мая 2024
Источник: nvd
CVSS3: 5.8
EPSS Низкий

Описание

Multiple Cisco products are affected by a vulnerability in the Snort Intrusion Prevention System (IPS) rule engine that could allow an unauthenticated, remote attacker to bypass the configured rules on an affected system. This vulnerability is due to incorrect HTTP packet handling. An attacker could exploit this vulnerability by sending crafted HTTP packets through an affected device. A successful exploit could allow the attacker to bypass configured IPS rules and allow uninspected traffic onto the network.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:cisco:firepower_threat_defense:7.4.0:*:*:*:*:*:*:*
Конфигурация 2

Одно из

cpe:2.3:o:cisco:unified_threat_defense_snort_intrusion_prevention_system_engine:17.6.4:*:*:*:*:*:*:*
cpe:2.3:o:cisco:unified_threat_defense_snort_intrusion_prevention_system_engine:17.6.5:*:*:*:*:*:*:*
cpe:2.3:o:cisco:unified_threat_defense_snort_intrusion_prevention_system_engine:17.12.1a:*:*:*:*:*:*:*
cpe:2.3:o:cisco:unified_threat_defense_snort_intrusion_prevention_system_engine:17.12.2:*:*:*:*:*:*:*
Конфигурация 3
cpe:2.3:a:cisco:snort:*:*:*:*:*:*:*:*
Версия от 3.0.0-233 (включая) до 3.1.69.0 (исключая)

EPSS

Процентиль: 35%
0.00143
Низкий

5.8 Medium

CVSS3

Дефекты

CWE-290
CWE-290

Связанные уязвимости

CVSS3: 5.8
github
больше 1 года назад

Multiple Cisco products are affected by a vulnerability in the Snort Intrusion Prevention System (IPS) rule engine that could allow an unauthenticated, remote attacker to bypass the configured rules on an affected system. This vulnerability is due to incorrect HTTP packet handling. An attacker could exploit this vulnerability by sending crafted HTTP packets through an affected device. A successful exploit could allow the attacker to bypass configured IPS rules and allow uninspected traffic onto the network.

CVSS3: 5.8
fstec
больше 1 года назад

Уязвимость функции контроля доступа системы обнаружения вторжений Snort, позволяющая нарушителю обойти существующие ограничения безопасности

EPSS

Процентиль: 35%
0.00143
Низкий

5.8 Medium

CVSS3

Дефекты

CWE-290
CWE-290