PT-2024-7507 · Cisco · Snort+1

Published

2024-10-23

·

Updated

2025-08-05

·

CVE-2024-20407

CVSS v3.1

5.8

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:C/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions: Cisco Firepower Threat Defense (FTD) Software (affected versions not specified)
Description: A logic error in the interaction between the TCP Intercept feature and the Snort 3 detection engine could allow an unauthenticated, remote attacker to bypass configured policies on an affected system. The issue arises from incorrect handling of embryonic (half-open) TCP connections. An attacker could exploit this by sending a crafted traffic pattern through an affected device, potentially allowing unintended traffic to enter the network. The vulnerability may also be related to incorrectly configured Maximum Embryonic TCP connections, which could enable a remote attacker to bypass security restrictions and perform a SYN flood attack.
Recommendations: At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Weakness Enumeration

Related Identifiers

BDU:2024-08896
CVE-2024-20407

Affected Products

Cisco Ftd
Snort