CVE-2024-20363
published 2024-05-22CVE-2024-20363: Multiple Cisco products are affected by a vulnerability in the Snort Intrusion Prevention System (IPS) rule engine that could allow an unauthenticated, remote…
PriorityP434medium5.8CVSS 3.1
AVNACLPRNUINSCCNILAN
EPSS
0.37%
29.2th percentile
Multiple Cisco products are affected by a vulnerability in the Snort Intrusion Prevention System (IPS) rule engine that could allow an unauthenticated, remote attacker to bypass the configured rules on an affected system. This vulnerability is due to incorrect HTTP packet handling. An attacker could exploit this vulnerability by sending crafted HTTP packets through an affected device. A successful exploit could allow the attacker to bypass configured IPS rules and allow uninspected traffic onto the network.
Affected
12 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | cisco_firepower_threat_defense_software | — | — |
| cisco | cisco_utd_snort_ips_engine_software | — | — |
| cisco | cisco_utd_snort_ips_engine_software | — | — |
| cisco | cisco_utd_snort_ips_engine_software | — | — |
| cisco | cisco_utd_snort_ips_engine_software | — | — |
| cisco | firepower_threat_defense | — | — |
| cisco | products_snort_3_http_intrusion_prevention_system_rule | — | — |
| cisco | snort | >= 3.0.0-233 < 3.1.69.0 | 3.1.69.0 |
| cisco | unified_threat_defense_snort_intrusion_prevention_system_engine | — | — |
| cisco | unified_threat_defense_snort_intrusion_prevention_system_engine | — | — |
| cisco | unified_threat_defense_snort_intrusion_prevention_system_engine | — | — |
| cisco | unified_threat_defense_snort_intrusion_prevention_system_engine | — | — |
CVSS provenance
nvdv3.15.8MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:L/A:N
vendor_cisco5.8MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-fgmg-8v8r-jj8g: Multiple Cisco products are affected by a vulnerability in the Snort Intrusion Prevention System (IPS) rule engine that could allow an unauthenticated
ghsa_unreviewed·2024-05-22
CVE-2024-20363 [MEDIUM] CWE-290 GHSA-fgmg-8v8r-jj8g: Multiple Cisco products are affected by a vulnerability in the Snort Intrusion Prevention System (IPS) rule engine that could allow an unauthenticated
Multiple Cisco products are affected by a vulnerability in the Snort Intrusion Prevention System (IPS) rule engine that could allow an unauthenticated, remote attacker to bypass the configured rules on an affected system. This vulnerability is due to incorrect HTTP packet handling. An attacker could exploit this vulnerability by sending crafted HTTP packets through an affected device. A successful exploit could allow the attacker to bypass configured IPS rules and allow uninspected traffic onto the network.
Cisco
Multiple Cisco Products Snort 3 HTTP Intrusion Prevention System Rule Bypass Vulnerability
vendor_cisco·2024-05-22·CVSS 5.8
CVE-2024-20363 [MEDIUM] CWE-290 Multiple Cisco Products Snort 3 HTTP Intrusion Prevention System Rule Bypass Vulnerability
Multiple Cisco Products Snort 3 HTTP Intrusion Prevention System Rule Bypass Vulnerability
Multiple Cisco products are affected by a vulnerability in the Snort Intrusion Prevention System (IPS) rule engine that could allow an unauthenticated, remote attacker to bypass the configured rules on an affected system.
This vulnerability is due to incorrect HTTP packet handling. An attacker could exploit this vulnerability by sending crafted HTTP packets through an affected device. A successful exploit could allow the attacker to bypass configured IPS rules and allow uninspected traffic onto the network.
Cisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability.
This advisory is available at the following link:https://sec.cloud
Cisco
Multiple Cisco Products Snort 3 HTTP Intrusion Prevention System Rule Bypass Vulnerability
vendor_cisco·CVSS 3.1
CVE-2024-20363 Multiple Cisco Products Snort 3 HTTP Intrusion Prevention System Rule Bypass Vulnerability
CVE-2024-20363: Multiple Cisco Products Snort 3 HTTP Intrusion Prevention System Rule Bypass Vulnerability
Multiple Cisco products are affected by a vulnerability in the Snort Intrusion Prevention System (IPS) rule engine that could allow an unauthenticated, remote attacker to bypass the configured rules on an affected system. This vulnerability is due to incorrect HTTP packet handling. An attacker could exploit this vulnerability by sending crafted HTTP packets through an affected device. A successful exploit could allow the attacker to bypass configured IPS rules and allow uninspected traffic onto the network. Cisco has released software updates that address this vulnerability. There are no
CVSS: 3.1
CWE: CWE-290, CWE-290
Bug IDs: CSCwh22565, CSCwh73244
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2024-05-22
Published