PT-2020-4710 · Cisco+1 · Cisco Ios Xe+5

Published

2020-10-21

·

Updated

2024-12-13

·

CVE-2020-3299

CVSS v3.1

5.8

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:C/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions: Cisco Firepower Threat Defense (FTD) versions (affected versions not specified) Cisco SD-WAN versions (affected versions not specified) Cisco IOS XE versions (affected versions not specified) Cisco Meraki versions (affected versions not specified)
Description: The issue is related to a vulnerability in the Snort detection engine that could allow an unauthenticated, remote attacker to bypass a configured File Policy for HTTP. This is due to incorrect detection of modified HTTP packets used in chunked responses. An attacker could exploit this by sending crafted HTTP packets through an affected device, potentially allowing them to bypass a configured File Policy for HTTP packets and deliver a malicious payload.
Recommendations: For Cisco Firepower Threat Defense (FTD), update to a version that includes a fix for the Snort detection engine vulnerability. For Cisco SD-WAN, apply the recommended configuration changes to mitigate the risk of exploitation until a patched version is available. For Cisco IOS XE, restrict access to HTTP packets to minimize the risk of exploitation until a fix is applied. For Cisco Meraki, consider disabling the Snort detection engine temporarily as a workaround until a patched version is released. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Protection Mechanism Failure

Weakness Enumeration

Related Identifiers

ALT-PU-2021-1678
ALT-PU-2024-16610
BDU:2020-05262
CVE-2020-3299
DLA-3317-1
DSA-5354-1
MGASA-2023-0117

Affected Products

Alt Linux
Cisco Ftd
Cisco Ios Xe
Cisco Meraki
Cisco Sd-Wan
Snort