CVE-2023-20177
Severity
4.0MEDIUM
EPSS
0.0%
top 99.20%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedNov 1
Description
A vulnerability in the SSL file policy implementation of Cisco Firepower Threat Defense (FTD) Software that occurs when the SSL/TLS connection is configured with a URL Category and the Snort 3 detection engine could allow an unauthenticated, remote attacker to cause the Snort 3 detection engine to unexpectedly restart. This vulnerability exists because a logic error occurs when a Snort 3 detection engine inspects an SSL/TLS connection that has either a URL Category configured on the SSL file pol…
CVSS vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:N/I:N/A:LExploitability: 2.2 | Impact: 1.4
Affected Packages2 packages
🔴Vulnerability Details
2CVEList▶
CVE-2023-20177: A vulnerability in the SSL file policy implementation of Cisco Firepower Threat Defense (FTD) Software that occurs when the SSL/TLS connection is conf↗2023-11-01
GHSA▶
GHSA-753m-gv8q-x327: A vulnerability in the SSL file policy implementation of Cisco Firepower Threat Defense (FTD) Software that occurs when the SSL/TLS connection is conf↗2023-11-01
📋Vendor Advisories
1Cisco▶
Cisco Firepower Threat Defense Software SSL/TLS URL Category and Snort 3 Detection Engine Bypass and Denial of Service Vulnerability↗2023-11-01