PT-2020-4700 · Cisco · Cisco Ftd+1

Published

2020-10-21

·

Updated

2023-08-16

·

CVE-2020-3564

CVSS v3.1

5.8

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:C/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions Cisco Firepower Threat Defense (FTD) Software (affected versions not specified) Cisco Adaptive Security Appliance (ASA) Software (affected versions not specified)
Description The issue is related to inadequate access control in the FTP inspection mechanism of the affected software, allowing a remote attacker to gain unauthorized access to protected information by sending specially crafted FTP traffic. This is due to ineffective flow tracking of FTP traffic, which could enable an attacker to bypass FTP inspection and successfully complete FTP connections.
Recommendations For Cisco Firepower Threat Defense (FTD) Software, update to a version that includes the fix for this issue. For Cisco Adaptive Security Appliance (ASA) Software, update to a version that includes the fix for this issue. As a temporary workaround, consider restricting access to the FTP inspection engine until a patch is available.

Fix

DoS

Improper Access Control

Improper Privilege Management

Weakness Enumeration

Related Identifiers

BDU:2020-05252
CVE-2020-3564

Affected Products

Cisco Asa
Cisco Ftd