CVE-2022-20730Improper Handling of Unexpected Data Type in Cisco Firepower Threat Defense

Severity
7.5HIGHNVD
CNA4.0
EPSS
0.3%
top 47.75%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMay 3
Latest updateMay 4

Description

A vulnerability in the Security Intelligence feed feature of Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to bypass the Security Intelligence DNS feed. This vulnerability is due to incorrect feed update processing. An attacker could exploit this vulnerability by sending traffic through an affected device that should be blocked by the affected device. A successful exploit could allow the attacker to bypass device controls and successfully send traf

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:NExploitability: 3.9 | Impact: 3.6

Affected Packages2 packages

🔴Vulnerability Details

2
GHSA
GHSA-94jr-h876-3jf2: A vulnerability in the Security Intelligence feed feature of Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote atta2022-05-04
CVEList
Cisco Firepower Threat Defense Software Security Intelligence DNS Feed Bypass Vulnerability2022-05-03

📋Vendor Advisories

1
Cisco
Cisco Firepower Threat Defense Software Security Intelligence DNS Feed Bypass Vulnerability2022-04-27
CVE-2022-20730 — Cisco vulnerability | cvebase