CVE-2024-20363
Multiple Cisco products are affected by a vulnerability in the Snort Intrusion Prevention System (IPS) rule engine that could allow an unauthenticated, remote attacker to bypass the configured rules o
Description
Multiple Cisco products are affected by a vulnerability in the Snort Intrusion Prevention System (IPS) rule engine that could allow an unauthenticated, remote attacker to bypass the configured rules on an affected system. This vulnerability is due to incorrect HTTP packet handling. An attacker could exploit this vulnerability by sending crafted HTTP packets through an affected device. A successful exploit could allow the attacker to bypass configured IPS rules and allow uninspected traffic onto the network.
Weakness: CWE-290
Affected products
| Vendor | Product | Category | Matched by |
|---|---|---|---|
| Cisco | Cisco Firepower Threat Defense (FTD) Check your version | Firewall / NGFW | cna-assigner |
| Cisco | Cisco UTD SNORT IPS Engine | Threat Detection & Sandbox | cna-assigner |
Vendor-reported products (7)
- Cisco · Cisco Firepower Threat Defense Software
- Cisco · Cisco UTD SNORT IPS Engine Software
- cisco · firepower_threat_defense
- cisco · snort_intrusion_prevention_system
- cisco · snort_intrusion_prevention_system
- cisco · snort_intrusion_prevention_system
- cisco · snort_intrusion_prevention_system
Vendor advisory
cisco-sa-snort3-ips-bypass-uE69KBMd
Multiple Cisco Products Snort 3 HTTP Intrusion Prevention System Rule Bypass Vulnerability
Cisco’s rating: Medium (advisory CVSS 5.8) · Published May 22, 2024
Bug IDs: CSCwh22565 , CSCwh73244
The vendor’s rating applies to the whole advisory and can differ from this CVE’s own CVSS severity. Where this comes from