PT-2023-7556 · Cisco · Cisco Asa+1

Published

2023-11-01

·

Updated

2024-01-25

·

CVE-2023-20245

CVSS v3.1

5.8

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:C/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions Cisco Adaptive Security Appliance (ASA) Software (affected versions not specified) Cisco Firepower Threat Defense (FTD) Software (affected versions not specified)
Description Multiple vulnerabilities in the per-user-override feature could allow an unauthenticated, remote attacker to bypass a configured access control list (ACL) and allow traffic that should be denied to flow through an affected device. These vulnerabilities are due to a logic error that could occur when the affected software constructs and applies per-user-override rules. An attacker could exploit these vulnerabilities by connecting to a network through an affected device that has a vulnerable configuration. A successful exploit could allow the attacker to bypass the interface ACL and access resources that would be protected.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Improper Access Control

Incorrect Privilege Assignment

Authentication Bypass by Spoofing

Weakness Enumeration

Related Identifiers

BDU:2023-08611
CVE-2023-20245

Affected Products

Cisco Asa
Cisco Ftd