CVE-2023-20071

MEDIUM

Cisco Firepower Threat Defense <6.4.0.17, Cyber Vision <4.1.3, UTD 17.3-17.3.8, Meraki MX FTP Inspection Bypass

Title source: llm
STIX 2.1

Description

Multiple Cisco products are affected by a vulnerability in the Snort detection engine that could allow an unauthenticated, remote attacker to bypass the configured policies on an affected system. This vulnerability is due to a flaw in the FTP module of the Snort detection engine. An attacker could exploit this vulnerability by sending crafted FTP traffic through an affected device. A successful exploit could allow the attacker to bypass FTP inspection and deliver a malicious payload.

Scores

CVSS v3 5.8
EPSS 0.0005
EPSS Percentile 14.6%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:L/A:N

Details

CWE
CWE-1039
Status published
Products (4)
cisco/cyber_vision < 4.1.3
cisco/firepower_threat_defense < 6.4.0.17
cisco/meraki_mx_security_appliance_firmware
cisco/unified_threat_defense 17.3 - 17.3.8
Published Nov 01, 2023
Tracked Since Feb 18, 2026