CVE-2023-20177

CWE-2444 documents4 sources
Severity
4.0MEDIUM
EPSS
0.0%
top 99.20%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedNov 1

Description

A vulnerability in the SSL file policy implementation of Cisco Firepower Threat Defense (FTD) Software that occurs when the SSL/TLS connection is configured with a URL Category and the Snort 3 detection engine could allow an unauthenticated, remote attacker to cause the Snort 3 detection engine to unexpectedly restart. This vulnerability exists because a logic error occurs when a Snort 3 detection engine inspects an SSL/TLS connection that has either a URL Category configured on the SSL file pol

CVSS vector

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:N/I:N/A:LExploitability: 2.2 | Impact: 1.4

Affected Packages2 packages

🔴Vulnerability Details

2
CVEList
CVE-2023-20177: A vulnerability in the SSL file policy implementation of Cisco Firepower Threat Defense (FTD) Software that occurs when the SSL/TLS connection is conf2023-11-01
GHSA
GHSA-753m-gv8q-x327: A vulnerability in the SSL file policy implementation of Cisco Firepower Threat Defense (FTD) Software that occurs when the SSL/TLS connection is conf2023-11-01

📋Vendor Advisories

1
Cisco
Cisco Firepower Threat Defense Software SSL/TLS URL Category and Snort 3 Detection Engine Bypass and Denial of Service Vulnerability2023-11-01
CVE-2023-20177 (MEDIUM CVSS 4) | A vulnerability in the SSL file pol | cvebase.io