PT-2020-4700 · Cisco · Cisco Ftd+1
Published
2020-10-21
·
Updated
2023-08-16
·
CVE-2020-3564
CVSS v3.1
5.8
Medium
| Vector | AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Cisco Firepower Threat Defense (FTD) Software (affected versions not specified)
Cisco Adaptive Security Appliance (ASA) Software (affected versions not specified)
Description
The issue is related to inadequate access control in the FTP inspection mechanism of the affected software, allowing a remote attacker to gain unauthorized access to protected information by sending specially crafted FTP traffic. This is due to ineffective flow tracking of FTP traffic, which could enable an attacker to bypass FTP inspection and successfully complete FTP connections.
Recommendations
For Cisco Firepower Threat Defense (FTD) Software, update to a version that includes the fix for this issue.
For Cisco Adaptive Security Appliance (ASA) Software, update to a version that includes the fix for this issue.
As a temporary workaround, consider restricting access to the FTP inspection engine until a patch is available.
Fix
DoS
Improper Access Control
Improper Privilege Management
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Cisco Asa
Cisco Ftd