CVE Database
/

CVE-2023-20245

Back to search

CVE-2023-20245

Published: Nov 1, 2023

Modified: Aug 2, 2024

PUBLISHED

CVSS v3.1

5.8

MEDIUM

Description

Multiple vulnerabilities in the per-user-override feature of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to bypass a configured access control list (ACL) and allow traffic that should be denied to flow through an affected device. These vulnerabilities are due to a logic error that could occur when the affected software constructs and applies per-user-override rules. An attacker could exploit these vulnerabilities by connecting to a network through an affected device that has a vulnerable configuration. A successful exploit could allow the attacker to bypass the interface ACL and access resources that would should be protected.

VendorProductVersions

Cisco

Cisco Adaptive Security Appliance (ASA) Software

affected
9.8.3.14
affected
9.8.3.16
affected
9.8.3.18
affected
9.8.3.21
affected
9.8.3.26

+137 more versions

Cisco

Cisco Firepower Threat Defense Software

affected
6.2.3.3
affected
6.2.3.4
affected
6.2.3.5
affected
6.2.3.6
affected
6.2.3.7

+63 more versions

Weaknesses (CWE)

CVSS v3.1 Details

CVSS v3.1 Vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:L/A:N

Attack Vector

Network

Attack Complexity

Low

Privileges Required

None

User Interaction

None

Scope

Changed

Confidentiality

None

Integrity

Low

Availability

None

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now