cbcvebase.
CVE-2020-3186
published 2020-05-06

CVE-2020-3186: A vulnerability in the management access list configuration of Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to…

medium5.3CVSS 3.1
AVNACLPRNUINSUCNILAN
A vulnerability in the management access list configuration of Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to bypass a configured management interface access list on an affected system. The vulnerability is due to the configuration of different management access lists, with ports allowed in one access list and denied in another. An attacker could exploit this vulnerability by sending crafted remote management traffic to the local IP address of an affected system. A successful exploit could allow the attacker to bypass the configured management access list policies, and traffic to the management interface would not be properly denied.

Affected

29 ranges· showing 25
VendorProductVersion rangeFixed in
ciscoasa_5505_firmware
ciscoasa_5505_firmware
ciscoasa_5510_firmware
ciscoasa_5510_firmware
ciscoasa_5512-x_firmware
ciscoasa_5512-x_firmware
ciscoasa_5515-x_firmware
ciscoasa_5515-x_firmware
ciscoasa_5520_firmware
ciscoasa_5520_firmware
ciscoasa_5525-x_firmware
ciscoasa_5525-x_firmware
ciscoasa_5540_firmware
ciscoasa_5540_firmware
ciscoasa_5545-x_firmware
ciscoasa_5545-x_firmware
ciscoasa_5550_firmware
ciscoasa_5550_firmware
ciscoasa_5555-x_firmware
ciscoasa_5555-x_firmware
ciscoasa_5580_firmware
ciscoasa_5580_firmware
ciscoasa_5585-x_firmware
ciscoasa_5585-x_firmware
ciscocisco_firepower_threat_defense_software