CVE-2024-20261 — Improper Access Control in Cisco Firepower Threat Defense Software
Severity
5.8MEDIUMNVD
EPSS
0.2%
top 58.87%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedMay 22
Description
A vulnerability in the file policy feature that is used to inspect encrypted archive files of Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to bypass a configured file policy to block an encrypted archive file. This vulnerability exists because of a logic error when a specific class of encrypted archive files is inspected. An attacker could exploit this vulnerability by sending a crafted, encrypted archive file through the affected device. A succes…
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:L/A:NExploitability: 3.9 | Impact: 1.4
Affected Packages2 packages
🔴Vulnerability Details
2GHSA▶
GHSA-q636-jcmg-x9g2: A vulnerability in the file policy feature that is used to inspect encrypted archive files of Cisco Firepower Threat Defense (FTD) Software could allo↗2024-05-22
CVEList▶
CVE-2024-20261: A vulnerability in the file policy feature that is used to inspect encrypted archive files of Cisco Firepower Threat Defense (FTD) Software could allo↗2024-05-22
📋Vendor Advisories
1Cisco▶
Cisco Firepower Threat Defense Software Encrypted Archive File Policy Bypass Vulnerability↗2024-05-22