Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2025-20268

Опубликовано: 14 авг. 2025
Источник: nvd
CVSS3: 5.8
EPSS Низкий

Описание

A vulnerability in the Geolocation-Based Remote Access (RA) VPN feature of Cisco Secure Firewall Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to bypass configured policies to allow or deny HTTP connections based on a country or region.

This vulnerability exists because the URL string is not fully parsed. An attacker could exploit this vulnerability by sending a crafted HTTP connection through the targeted device. A successful exploit could allow the attacker to bypass configured policies and gain access to a network where the connection should have been denied.

EPSS

Процентиль: 11%
0.00036
Низкий

5.8 Medium

CVSS3

Дефекты

CWE-229

Связанные уязвимости

CVSS3: 5.8
github
6 месяцев назад

A vulnerability in the Geolocation-Based Remote Access (RA) VPN feature of Cisco Secure Firewall Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to bypass configured policies to allow or deny HTTP connections based on a country or region. This vulnerability exists because the URL string is not fully parsed. An attacker could exploit this vulnerability by sending a crafted HTTP connection through the targeted device. A successful exploit could allow the attacker to bypass configured policies and gain access to a network where the connection should have been denied.

CVSS3: 5.8
fstec
6 месяцев назад

Уязвимость функции Geolocation-Based RA VPN микропрограммного обеспечения межсетевых экранов Cisco Firepower Threat Defense (FTD), позволяющая нарушителю обойти ограничения безопасности

EPSS

Процентиль: 11%
0.00036
Низкий

5.8 Medium

CVSS3

Дефекты

CWE-229