CVE-2022-20730
published 2022-05-03CVE-2022-20730: A vulnerability in the Security Intelligence feed feature of Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to…
PriorityP348high7.5CVSS 3.1
AVNACLPRNUINSUCNIHAN
EPSS
0.91%
56.1th percentile
A vulnerability in the Security Intelligence feed feature of Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to bypass the Security Intelligence DNS feed. This vulnerability is due to incorrect feed update processing. An attacker could exploit this vulnerability by sending traffic through an affected device that should be blocked by the affected device. A successful exploit could allow the attacker to bypass device controls and successfully send traffic to devices that are expected to be protected by the affected device.
Affected
5 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | cisco_firepower_threat_defense_software | — | — |
| cisco | firepower_threat_defense | < 6.4.0.15 | 6.4.0.15 |
| cisco | firepower_threat_defense | — | — |
| cisco | firepower_threat_defense | >= 6.5.0 < 6.6.5.2 | 6.6.5.2 |
| cisco | firepower_threat_defense | >= 6.7.0 < 7.0.2 | 7.0.2 |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:P/A:N
vendor_cisco4.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-94jr-h876-3jf2: A vulnerability in the Security Intelligence feed feature of Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote atta
ghsa_unreviewed·2022-05-04
CVE-2022-20730 [HIGH] GHSA-94jr-h876-3jf2: A vulnerability in the Security Intelligence feed feature of Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote atta
A vulnerability in the Security Intelligence feed feature of Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to bypass the Security Intelligence DNS feed. This vulnerability is due to incorrect feed update processing. An attacker could exploit this vulnerability by sending traffic through an affected device that should be blocked by the affected device. A successful exploit could allow the attacker to bypass device controls and successfully send traffic to devices that are expected to be protected by the affected device.
Cisco
Cisco Firepower Threat Defense Software Security Intelligence DNS Feed Bypass Vulnerability
vendor_cisco·2022-04-27·CVSS 4.0
CVE-2022-20730 [MEDIUM] CWE-241 Cisco Firepower Threat Defense Software Security Intelligence DNS Feed Bypass Vulnerability
Cisco Firepower Threat Defense Software Security Intelligence DNS Feed Bypass Vulnerability
A vulnerability in the Security Intelligence feed feature of Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to bypass the Security Intelligence DNS feed.
This vulnerability is due to incorrect feed update processing. An attacker could exploit this vulnerability by sending traffic through an affected device that should be blocked by the affected device. A successful exploit could allow the attacker to bypass device controls and successfully send traffic to devices that are expected to be protected by the affected device.
Cisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability.
This a
Cisco
Cisco Firepower Threat Defense Software Security Intelligence DNS Feed Bypass Vulnerability
vendor_cisco·CVSS 3.1
CVE-2022-20730 Cisco Firepower Threat Defense Software Security Intelligence DNS Feed Bypass Vulnerability
CVE-2022-20730: Cisco Firepower Threat Defense Software Security Intelligence DNS Feed Bypass Vulnerability
A vulnerability in the Security Intelligence feed feature of Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to bypass the Security Intelligence DNS feed. This vulnerability is due to incorrect feed update processing. An attacker could exploit this vulnerability by sending traffic through an affected device that should be blocked by the affected device. A successful exploit could allow the attacker to bypass device controls and successfully send traffic to devices that are expected to be protected by the affected device. Cisco has released software updates that address this vulnerability. There are no
CVSS: 3.1
CWE: CWE-241, CWE-241
Bug I
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2022-05-03
Published