CVE-2024-20363
Last modified
CVE-2024-20363 is a medium-severity vulnerability rated 5.8/10 on the CVSS scale. Multiple Cisco products are affected by a vulnerability in the Snort Intrusion Prevention System (IPS) rule engine that could allow an unauthenticated, remote attacker to bypass the configured rules on an affected system. This vulnerability is due to incorrect HTTP packet handling. EPSS estimates a 0.37% chance of exploitation in the next 30 days.
Description
Multiple Cisco products are affected by a vulnerability in the Snort Intrusion Prevention System (IPS) rule engine that could allow an unauthenticated, remote attacker to bypass the configured rules on an affected system. This vulnerability is due to incorrect HTTP packet handling. An attacker could exploit this vulnerability by sending crafted HTTP packets through an affected device. A successful exploit could allow the attacker to bypass configured IPS rules and allow uninspected traffic onto the network.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:L/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Cisco | Firepower Threat Defense | 7.4.0 |
| Cisco | Unified Threat Defense Snort Intrusion Prevention System Engine | 17.6.4 |
| Cisco | Unified Threat Defense Snort Intrusion Prevention System Engine | 17.6.5 |
| Cisco | Unified Threat Defense Snort Intrusion Prevention System Engine | 17.12.1a |
| Cisco | Unified Threat Defense Snort Intrusion Prevention System Engine | 17.12.2 |
| Cisco | Snort | >= 3.0.0-233, < 3.1.69.0 |
References
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2024-20363?
How severe is CVE-2024-20363?
How do I fix CVE-2024-20363?
How Strix Helps
- Same Subject, Wrong User: A Cross-Issuer Account Takeover in n8nStrix found an identity-binding bug in n8n's token-exchange flow enabling account takeover.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2024
- CVE-2024-20358A vulnerability in the Cisco Adaptive Security Appliance (AS…6.7
- CVE-2024-20359A vulnerability in a legacy capability that allowed for the …6
- CVE-2024-2036The ApplyOnline – Application Form Builder and Manager plugi…4.3
- CVE-2024-20360A vulnerability in the web-based management interface of Cis…8.8
- CVE-2024-20361A vulnerability in the Object Groups for Access Control List…5.8
- CVE-2024-20362A vulnerability in the web-based management interface of Cis…6.1
- CVE-2024-20364A vulnerability in the web-based management interface of Cis…5.4
- CVE-2024-20365A vulnerability in the Redfish API of Cisco UCS B-Series, Ci…7.2
- CVE-2024-20366A vulnerability in the Tail-f High Availability Cluster Comm…7.8
- CVE-2024-20367A vulnerability in the web UI of Cisco Enterprise Chat and E…5.4
- CVE-2024-20368A vulnerability in the web-based management interface of Cis…8.8
- CVE-2024-20369A vulnerability in the web-based management interface of Cis…6.1
Are you affected by CVE-2024-20363?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
