CVE-2024-20508
published 2024-09-25CVE-2024-20508: A vulnerability in Cisco Unified Threat Defense (UTD) Snort Intrusion Prevention System (IPS) Engine for Cisco IOS XE Software could allow an unauthenticated…
PriorityP336medium6.5CVSS 3.1
AVNACLPRNUINSUCNILAL
EPSS
0.42%
33.7th percentile
A vulnerability in Cisco Unified Threat Defense (UTD) Snort Intrusion Prevention System (IPS) Engine for Cisco IOS XE Software could allow an unauthenticated, remote attacker to bypass configured security policies or cause a denial of service (DoS) condition on an affected device.
This vulnerability is due to insufficient validation of HTTP requests when they are processed by Cisco UTD Snort IPS Engine. An attacker could exploit this vulnerability by sending a crafted HTTP request through an affected device. A successful exploit could allow the attacker to trigger a reload of the Snort process. If the action in case of Cisco UTD Snort IPS Engine failure is set to the default, fail-open, successful exploitation of this vulnerability could allow the attacker to bypass configured security policies. If the action in case of Cisco UTD Snort IPS Engine failure is set to fail-close, successful exploitation of this vulnerability could cause traffic that is configured to be inspected by Cisco UTD Snort IPS Engine to be dropped.
Affected
33 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | cisco_utd_snort_ips_engine_software | — | — |
| cisco | cisco_utd_snort_ips_engine_software | — | — |
| cisco | cisco_utd_snort_ips_engine_software | — | — |
| cisco | cisco_utd_snort_ips_engine_software | — | — |
| cisco | cisco_utd_snort_ips_engine_software | — | — |
| cisco | cisco_utd_snort_ips_engine_software | — | — |
| cisco | cisco_utd_snort_ips_engine_software | — | — |
| cisco | cisco_utd_snort_ips_engine_software | — | — |
| cisco | cisco_utd_snort_ips_engine_software | — | — |
| cisco | cisco_utd_snort_ips_engine_software | — | — |
| cisco | cisco_utd_snort_ips_engine_software | — | — |
| cisco | cisco_utd_snort_ips_engine_software | — | — |
| cisco | cisco_utd_snort_ips_engine_software | — | — |
| cisco | cisco_utd_snort_ips_engine_software | — | — |
| cisco | cisco_utd_snort_ips_engine_software | — | — |
| cisco | cisco_utd_snort_ips_engine_software | — | — |
| cisco | unified_threat_defense_snort_intrusion_prevention_system_engine | — | — |
| cisco | unified_threat_defense_snort_intrusion_prevention_system_engine | — | — |
| cisco | unified_threat_defense_snort_intrusion_prevention_system_engine | — | — |
| cisco | unified_threat_defense_snort_intrusion_prevention_system_engine | — | — |
| cisco | unified_threat_defense_snort_intrusion_prevention_system_engine | — | — |
| cisco | unified_threat_defense_snort_intrusion_prevention_system_engine | — | — |
| cisco | unified_threat_defense_snort_intrusion_prevention_system_engine | — | — |
| cisco | unified_threat_defense_snort_intrusion_prevention_system_engine | — | — |
| cisco | unified_threat_defense_snort_intrusion_prevention_system_engine | — | — |
CVSS provenance
nvdv3.16.5MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L
vendor_cisco5.8MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Cisco
Cisco Unified Threat Defense Snort Intrusion Prevention System Engine for Cisco IOS XE Software Security Policy Bypass and Denial of Service Vulnerability
vendor_cisco·2024-09-25·CVSS 5.8
CVE-2024-20508 [MEDIUM] CWE-122 Cisco Unified Threat Defense Snort Intrusion Prevention System Engine for Cisco IOS XE Software Security Policy Bypass and Denial of Service Vulnerability
Cisco Unified Threat Defense Snort Intrusion Prevention System Engine for Cisco IOS XE Software Security Policy Bypass and Denial of Service Vulnerability
A vulnerability in Cisco Unified Threat Defense (UTD) Snort Intrusion Prevention System (IPS) Engine for Cisco IOS XE Software could allow an unauthenticated, remote attacker to bypass configured security policies or cause a denial of service (DoS) condition on an affected device.
This vulnerability is due to insufficient validation of HTTP requests when they are processed by Cisco UTD Snort IPS Engine. An attacker could exploit this vulnerability by sending a crafted HTTP request through an affected device. A successful exploit could allow the attacker to trigger a reload of the Snort process. If the action in case of Cisco UTD Snort
Cisco
Cisco Unified Threat Defense Snort Intrusion Prevention System Engine for Cisco IOS XE Software Security Policy Bypass and Denial of Service Vulnerability
vendor_cisco·CVSS 3.1
CVE-2024-20508 Cisco Unified Threat Defense Snort Intrusion Prevention System Engine for Cisco IOS XE Software Security Policy Bypass and Denial of Service Vulnerability
CVE-2024-20508: Cisco Unified Threat Defense Snort Intrusion Prevention System Engine for Cisco IOS XE Software Security Policy Bypass and Denial of Service Vulnerability
A vulnerability in Cisco Unified Threat Defense (UTD) Snort Intrusion Prevention System (IPS) Engine for Cisco IOS XE Software could allow an unauthenticated, remote attacker to bypass configured security policies or cause a denial of service (DoS) condition on an affected device. This vulnerability is due to insufficient validation of HTTP requests when they are processed by Cisco UTD Snort IPS Engine. An attacker could exploit this vulnerability by sending a crafted HTTP request through an affected device. A successful exploit could allow the attacker to trigger a reload of the Snort process. If the action in case of Ci
GHSA
GHSA-fmxj-97w3-xq3m: A vulnerability in Cisco Unified Threat Defense (UTD) Snort Intrusion Prevention System (IPS) Engine for Cisco IOS XE Software could allow an unauthen
ghsa_unreviewed·2024-09-25
CVE-2024-20508 [MEDIUM] CWE-122 GHSA-fmxj-97w3-xq3m: A vulnerability in Cisco Unified Threat Defense (UTD) Snort Intrusion Prevention System (IPS) Engine for Cisco IOS XE Software could allow an unauthen
A vulnerability in Cisco Unified Threat Defense (UTD) Snort Intrusion Prevention System (IPS) Engine for Cisco IOS XE Software could allow an unauthenticated, remote attacker to bypass configured security policies or cause a denial of service (DoS) condition on an affected device.
This vulnerability is due to insufficient validation of HTTP requests when they are processed by Cisco UTD Snort IPS Engine. An attacker could exploit this vulnerability by sending a crafted HTTP request through an affected device. A successful exploit could allow the attacker to trigger a reload of the Snort process. If the action in case of Cisco UTD Snort IPS Engine failure is set to the default, fail-open, successful exploitation of this vulnerability could allow the attacker to bypass configured security po
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2024-09-25
Published