CVE-2023-20071
MEDIUMCisco Firepower Threat Defense <6.4.0.17, Cyber Vision <4.1.3, UTD 17.3-17.3.8, Meraki MX FTP Inspection Bypass
Title source: llmDescription
Multiple Cisco products are affected by a vulnerability in the Snort detection engine that could allow an unauthenticated, remote attacker to bypass the configured policies on an affected system. This vulnerability is due to a flaw in the FTP module of the Snort detection engine. An attacker could exploit this vulnerability by sending crafted FTP traffic through an affected device. A successful exploit could allow the attacker to bypass FTP inspection and deliver a malicious payload.
References (1)
Core 1
Core References
Scores
CVSS v3
5.8
EPSS
0.0005
EPSS Percentile
14.6%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:L/A:N
Details
CWE
CWE-1039
Status
published
Products (4)
cisco/cyber_vision
< 4.1.3
cisco/firepower_threat_defense
< 6.4.0.17
cisco/meraki_mx_security_appliance_firmware
cisco/unified_threat_defense
17.3 - 17.3.8
Published
Nov 01, 2023
Tracked Since
Feb 18, 2026