CVE-2024-20508
Cisco UTD Snort IPS Engine Software for Cisco IOS XE Software Security Policy Bypass and Denial of Service Vulnerability
Description
A vulnerability in Cisco Unified Threat Defense (UTD) Snort Intrusion Prevention System (IPS) Engine for Cisco IOS XE Software could allow an unauthenticated, remote attacker to bypass configured security policies or cause a denial of service (DoS) condition on an affected device. This vulnerability is due to insufficient validation of HTTP requests when they are processed by Cisco UTD Snort IPS Engine. An attacker could exploit this vulnerability by sending a crafted HTTP request through an affected device. A successful exploit could allow the attacker to trigger a reload of the Snort process. If the action in case of Cisco UTD Snort IPS Engine failure is set to the default, fail-open, successful exploitation of this vulnerability could allow the attacker to bypass configured security policies. If the action in case of Cisco UTD Snort IPS Engine failure is set to fail-close, successful exploitation of this vulnerability could cause traffic that is configured to be inspected by Cisco UTD Snort IPS Engine to be dropped.
Weakness: CWE-122
Affected products
| Vendor | Product | Category | Matched by |
|---|---|---|---|
| Cisco | Cisco UTD SNORT IPS Engine | Threat Detection & Sandbox | cna-assigner |
Vendor-reported products (2)
- Cisco · Cisco UTD SNORT IPS Engine Software
- cisco · cisco_utd_snort_ips_engine_software
Vendor advisory
cisco-sa-utd-snort3-dos-bypas-b4OUEwxD
Cisco Unified Threat Defense Snort Intrusion Prevention System Engine for Cisco IOS XE Software Security Policy Bypass and Denial of Service Vulnerability
Cisco’s rating: Medium (advisory CVSS 5.8) · Published Sep 25, 2024
Bug ID: CSCwj21273
The vendor’s rating applies to the whole advisory and can differ from this CVE’s own CVSS severity. Where this comes from