PT-2020-4710 · Cisco+1 · Cisco Ios Xe+5
Published
2020-10-21
·
Updated
2024-12-13
·
CVE-2020-3299
CVSS v3.1
5.8
Medium
| Vector | AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:L/A:N |
Name of the Vulnerable Software and Affected Versions:
Cisco Firepower Threat Defense (FTD) versions (affected versions not specified)
Cisco SD-WAN versions (affected versions not specified)
Cisco IOS XE versions (affected versions not specified)
Cisco Meraki versions (affected versions not specified)
Description:
The issue is related to a vulnerability in the Snort detection engine that could allow an unauthenticated, remote attacker to bypass a configured File Policy for HTTP. This is due to incorrect detection of modified HTTP packets used in chunked responses. An attacker could exploit this by sending crafted HTTP packets through an affected device, potentially allowing them to bypass a configured File Policy for HTTP packets and deliver a malicious payload.
Recommendations:
For Cisco Firepower Threat Defense (FTD), update to a version that includes a fix for the Snort detection engine vulnerability.
For Cisco SD-WAN, apply the recommended configuration changes to mitigate the risk of exploitation until a patched version is available.
For Cisco IOS XE, restrict access to HTTP packets to minimize the risk of exploitation until a fix is applied.
For Cisco Meraki, consider disabling the Snort detection engine temporarily as a workaround until a patched version is released.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Protection Mechanism Failure
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Alt Linux
Cisco Ftd
Cisco Ios Xe
Cisco Meraki
Cisco Sd-Wan
Snort