PT-2020-2236 · Cisco · Cisco Ios+3

Published

2020-05-05

·

Updated

2024-11-26

·

CVE-2020-3315

CVSS v3.1

5.8

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:C/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions Cisco IOS versions prior to the fixed version Cisco Firepower Threat Defense versions prior to the fixed version Cisco Firepower Management Center versions prior to the fixed version
Description The issue is related to errors in how the Snort detection engine handles specific HTTP responses, allowing an unauthenticated, remote attacker to bypass the configured file policies on an affected system. An attacker could exploit this by sending crafted HTTP packets that would flow through an affected system, potentially delivering a malicious payload to the protected network.
Recommendations For Cisco IOS, update to a version that includes the fix for this issue. For Cisco Firepower Threat Defense, update to a version that includes the fix for this issue. For Cisco Firepower Management Center, update to a version that includes the fix for this issue. As a temporary workaround, consider restricting access to the Snort detection engine until a patch is available.

Fix

Protection Mechanism Failure

Exposure of Resource to Wrong Sphere

Weakness Enumeration

Related Identifiers

BDU:2020-02152
CVE-2020-3315
DLA-3317-1
DSA-5354-1
MGASA-2023-0117

Affected Products

Cisco Firepower Management Center
Cisco Ftd
Cisco Ios
Snort