CVE-2020-3315
Multiple Cisco Products Snort HTTP Detection Engine File Policy Bypass Vulnerability
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
Multiple Cisco products are affected by a vulnerability in the Snort detection engine that could allow an unauthenticated, remote attacker to bypass the configured file policies on an affected system. The vulnerability is due to errors in how the Snort detection engine handles specific HTTP responses. An attacker could exploit this vulnerability by sending crafted HTTP packets that would flow through an affected system. A successful exploit could allow the attacker to bypass the configured file policies and deliver a malicious payload to the protected network.
Múltiples productos de Cisco están afectados por una vulnerabilidad en el motor de detección Snort que podría permitir a un atacante remoto no autenticado omitir las políticas de archivos configuradas sobre un sistema afectado. La vulnerabilidad es debido a errores en como el motor de detección Snort maneja respuestas HTTP específicas. Un atacante podría explotar esta vulnerabilidad mediante el envío de paquetes HTTP diseñados que fluirían por medio de un sistema afectado. Una explotación con éxito podría permitir a un atacante omitir las políticas de archivos configuradas y entregar una carga maliciosa a la red protegida.
CVSS Scores
SSVC
- Decision:Attend
Timeline
- 2019-12-12 CVE Reserved
- 2020-05-06 CVE Published
- 2024-02-24 EPSS Updated
- 2024-11-15 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-668: Exposure of Resource to Wrong Sphere
- CWE-693: Protection Mechanism Failure
CAPEC
References (3)
URL | Tag | Source |
---|---|---|
https://lists.debian.org/debian-lts-announce/2023/02/msg00011.html | Mailing List |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Cisco Search vendor "Cisco" | Ios Search vendor "Cisco" for product "Ios" | 15.2\(7\)e Search vendor "Cisco" for product "Ios" and version "15.2\(7\)e" | - |
Affected
| in | Cisco Search vendor "Cisco" | 1100-4g Integrated Services Router Search vendor "Cisco" for product "1100-4g Integrated Services Router" | - | - |
Safe
|
Cisco Search vendor "Cisco" | Ios Search vendor "Cisco" for product "Ios" | 15.2\(7\)e Search vendor "Cisco" for product "Ios" and version "15.2\(7\)e" | - |
Affected
| in | Cisco Search vendor "Cisco" | 1100-6g Integrated Services Router Search vendor "Cisco" for product "1100-6g Integrated Services Router" | - | - |
Safe
|
Cisco Search vendor "Cisco" | Ios Search vendor "Cisco" for product "Ios" | 15.2\(7\)e Search vendor "Cisco" for product "Ios" and version "15.2\(7\)e" | - |
Affected
| in | Cisco Search vendor "Cisco" | 1100-lte Integrated Services Router Search vendor "Cisco" for product "1100-lte Integrated Services Router" | - | - |
Safe
|
Cisco Search vendor "Cisco" | Ios Search vendor "Cisco" for product "Ios" | 15.2\(7\)e Search vendor "Cisco" for product "Ios" and version "15.2\(7\)e" | - |
Affected
| in | Cisco Search vendor "Cisco" | 1101 Integrated Services Router Search vendor "Cisco" for product "1101 Integrated Services Router" | - | - |
Safe
|
Cisco Search vendor "Cisco" | Ios Search vendor "Cisco" for product "Ios" | 15.2\(7\)e Search vendor "Cisco" for product "Ios" and version "15.2\(7\)e" | - |
Affected
| in | Cisco Search vendor "Cisco" | 1109 Integrated Services Router Search vendor "Cisco" for product "1109 Integrated Services Router" | - | - |
Safe
|
Cisco Search vendor "Cisco" | Ios Search vendor "Cisco" for product "Ios" | 15.2\(7\)e Search vendor "Cisco" for product "Ios" and version "15.2\(7\)e" | - |
Affected
| in | Cisco Search vendor "Cisco" | 1111x Integrated Services Router Search vendor "Cisco" for product "1111x Integrated Services Router" | - | - |
Safe
|
Cisco Search vendor "Cisco" | Ios Search vendor "Cisco" for product "Ios" | 15.2\(7\)e Search vendor "Cisco" for product "Ios" and version "15.2\(7\)e" | - |
Affected
| in | Cisco Search vendor "Cisco" | 111x Integrated Services Router Search vendor "Cisco" for product "111x Integrated Services Router" | - | - |
Safe
|
Cisco Search vendor "Cisco" | Ios Search vendor "Cisco" for product "Ios" | 15.2\(7\)e Search vendor "Cisco" for product "Ios" and version "15.2\(7\)e" | - |
Affected
| in | Cisco Search vendor "Cisco" | 1120 Integrated Services Router Search vendor "Cisco" for product "1120 Integrated Services Router" | - | - |
Safe
|
Cisco Search vendor "Cisco" | Ios Search vendor "Cisco" for product "Ios" | 15.2\(7\)e Search vendor "Cisco" for product "Ios" and version "15.2\(7\)e" | - |
Affected
| in | Cisco Search vendor "Cisco" | 1160 Integrated Services Router Search vendor "Cisco" for product "1160 Integrated Services Router" | - | - |
Safe
|
Cisco Search vendor "Cisco" | Ios Search vendor "Cisco" for product "Ios" | 15.2\(7\)e Search vendor "Cisco" for product "Ios" and version "15.2\(7\)e" | - |
Affected
| in | Cisco Search vendor "Cisco" | 4221 Integrated Services Router Search vendor "Cisco" for product "4221 Integrated Services Router" | - | - |
Safe
|
Cisco Search vendor "Cisco" | Ios Search vendor "Cisco" for product "Ios" | 15.2\(7\)e Search vendor "Cisco" for product "Ios" and version "15.2\(7\)e" | - |
Affected
| in | Cisco Search vendor "Cisco" | 4331 Integrated Services Router Search vendor "Cisco" for product "4331 Integrated Services Router" | - | - |
Safe
|
Cisco Search vendor "Cisco" | Ios Search vendor "Cisco" for product "Ios" | 15.2\(7\)e Search vendor "Cisco" for product "Ios" and version "15.2\(7\)e" | - |
Affected
| in | Cisco Search vendor "Cisco" | 4431 Integrated Services Router Search vendor "Cisco" for product "4431 Integrated Services Router" | - | - |
Safe
|
Cisco Search vendor "Cisco" | Ios Search vendor "Cisco" for product "Ios" | 15.2\(7\)e Search vendor "Cisco" for product "Ios" and version "15.2\(7\)e" | - |
Affected
| in | Cisco Search vendor "Cisco" | 4461 Integrated Services Router Search vendor "Cisco" for product "4461 Integrated Services Router" | - | - |
Safe
|
Cisco Search vendor "Cisco" | Ios Search vendor "Cisco" for product "Ios" | 15.2\(7\)e Search vendor "Cisco" for product "Ios" and version "15.2\(7\)e" | - |
Affected
| in | Cisco Search vendor "Cisco" | Csr1000v Search vendor "Cisco" for product "Csr1000v" | - | - |
Safe
|
Cisco Search vendor "Cisco" | Ios Search vendor "Cisco" for product "Ios" | 15.2\(7\)e Search vendor "Cisco" for product "Ios" and version "15.2\(7\)e" | - |
Affected
| in | Cisco Search vendor "Cisco" | Isa-3000-2c2f-k9 Search vendor "Cisco" for product "Isa-3000-2c2f-k9" | - | - |
Safe
|
Cisco Search vendor "Cisco" | Ios Search vendor "Cisco" for product "Ios" | 15.2\(7\)e Search vendor "Cisco" for product "Ios" and version "15.2\(7\)e" | - |
Affected
| in | Cisco Search vendor "Cisco" | Isa-3000-4c-k9 Search vendor "Cisco" for product "Isa-3000-4c-k9" | - | - |
Safe
|
Cisco Search vendor "Cisco" | Ios Search vendor "Cisco" for product "Ios" | 16.11.2 Search vendor "Cisco" for product "Ios" and version "16.11.2" | - |
Affected
| in | Cisco Search vendor "Cisco" | 1100-4g Integrated Services Router Search vendor "Cisco" for product "1100-4g Integrated Services Router" | - | - |
Safe
|
Cisco Search vendor "Cisco" | Ios Search vendor "Cisco" for product "Ios" | 16.11.2 Search vendor "Cisco" for product "Ios" and version "16.11.2" | - |
Affected
| in | Cisco Search vendor "Cisco" | 1100-6g Integrated Services Router Search vendor "Cisco" for product "1100-6g Integrated Services Router" | - | - |
Safe
|
Cisco Search vendor "Cisco" | Ios Search vendor "Cisco" for product "Ios" | 16.11.2 Search vendor "Cisco" for product "Ios" and version "16.11.2" | - |
Affected
| in | Cisco Search vendor "Cisco" | 1100-lte Integrated Services Router Search vendor "Cisco" for product "1100-lte Integrated Services Router" | - | - |
Safe
|
Cisco Search vendor "Cisco" | Ios Search vendor "Cisco" for product "Ios" | 16.11.2 Search vendor "Cisco" for product "Ios" and version "16.11.2" | - |
Affected
| in | Cisco Search vendor "Cisco" | 1101 Integrated Services Router Search vendor "Cisco" for product "1101 Integrated Services Router" | - | - |
Safe
|
Cisco Search vendor "Cisco" | Ios Search vendor "Cisco" for product "Ios" | 16.11.2 Search vendor "Cisco" for product "Ios" and version "16.11.2" | - |
Affected
| in | Cisco Search vendor "Cisco" | 1109 Integrated Services Router Search vendor "Cisco" for product "1109 Integrated Services Router" | - | - |
Safe
|
Cisco Search vendor "Cisco" | Ios Search vendor "Cisco" for product "Ios" | 16.11.2 Search vendor "Cisco" for product "Ios" and version "16.11.2" | - |
Affected
| in | Cisco Search vendor "Cisco" | 1111x Integrated Services Router Search vendor "Cisco" for product "1111x Integrated Services Router" | - | - |
Safe
|
Cisco Search vendor "Cisco" | Ios Search vendor "Cisco" for product "Ios" | 16.11.2 Search vendor "Cisco" for product "Ios" and version "16.11.2" | - |
Affected
| in | Cisco Search vendor "Cisco" | 111x Integrated Services Router Search vendor "Cisco" for product "111x Integrated Services Router" | - | - |
Safe
|
Cisco Search vendor "Cisco" | Ios Search vendor "Cisco" for product "Ios" | 16.11.2 Search vendor "Cisco" for product "Ios" and version "16.11.2" | - |
Affected
| in | Cisco Search vendor "Cisco" | 1120 Integrated Services Router Search vendor "Cisco" for product "1120 Integrated Services Router" | - | - |
Safe
|
Cisco Search vendor "Cisco" | Ios Search vendor "Cisco" for product "Ios" | 16.11.2 Search vendor "Cisco" for product "Ios" and version "16.11.2" | - |
Affected
| in | Cisco Search vendor "Cisco" | 1160 Integrated Services Router Search vendor "Cisco" for product "1160 Integrated Services Router" | - | - |
Safe
|
Cisco Search vendor "Cisco" | Ios Search vendor "Cisco" for product "Ios" | 16.11.2 Search vendor "Cisco" for product "Ios" and version "16.11.2" | - |
Affected
| in | Cisco Search vendor "Cisco" | 4221 Integrated Services Router Search vendor "Cisco" for product "4221 Integrated Services Router" | - | - |
Safe
|
Cisco Search vendor "Cisco" | Ios Search vendor "Cisco" for product "Ios" | 16.11.2 Search vendor "Cisco" for product "Ios" and version "16.11.2" | - |
Affected
| in | Cisco Search vendor "Cisco" | 4331 Integrated Services Router Search vendor "Cisco" for product "4331 Integrated Services Router" | - | - |
Safe
|
Cisco Search vendor "Cisco" | Ios Search vendor "Cisco" for product "Ios" | 16.11.2 Search vendor "Cisco" for product "Ios" and version "16.11.2" | - |
Affected
| in | Cisco Search vendor "Cisco" | 4431 Integrated Services Router Search vendor "Cisco" for product "4431 Integrated Services Router" | - | - |
Safe
|
Cisco Search vendor "Cisco" | Ios Search vendor "Cisco" for product "Ios" | 16.11.2 Search vendor "Cisco" for product "Ios" and version "16.11.2" | - |
Affected
| in | Cisco Search vendor "Cisco" | 4461 Integrated Services Router Search vendor "Cisco" for product "4461 Integrated Services Router" | - | - |
Safe
|
Cisco Search vendor "Cisco" | Ios Search vendor "Cisco" for product "Ios" | 16.11.2 Search vendor "Cisco" for product "Ios" and version "16.11.2" | - |
Affected
| in | Cisco Search vendor "Cisco" | Csr1000v Search vendor "Cisco" for product "Csr1000v" | - | - |
Safe
|
Cisco Search vendor "Cisco" | Ios Search vendor "Cisco" for product "Ios" | 16.11.2 Search vendor "Cisco" for product "Ios" and version "16.11.2" | - |
Affected
| in | Cisco Search vendor "Cisco" | Isa-3000-2c2f-k9 Search vendor "Cisco" for product "Isa-3000-2c2f-k9" | - | - |
Safe
|
Cisco Search vendor "Cisco" | Ios Search vendor "Cisco" for product "Ios" | 16.11.2 Search vendor "Cisco" for product "Ios" and version "16.11.2" | - |
Affected
| in | Cisco Search vendor "Cisco" | Isa-3000-4c-k9 Search vendor "Cisco" for product "Isa-3000-4c-k9" | - | - |
Safe
|
Cisco Search vendor "Cisco" | Ios Search vendor "Cisco" for product "Ios" | 17.3.1 Search vendor "Cisco" for product "Ios" and version "17.3.1" | - |
Affected
| in | Cisco Search vendor "Cisco" | 1100-4g Integrated Services Router Search vendor "Cisco" for product "1100-4g Integrated Services Router" | - | - |
Safe
|
Cisco Search vendor "Cisco" | Ios Search vendor "Cisco" for product "Ios" | 17.3.1 Search vendor "Cisco" for product "Ios" and version "17.3.1" | - |
Affected
| in | Cisco Search vendor "Cisco" | 1100-6g Integrated Services Router Search vendor "Cisco" for product "1100-6g Integrated Services Router" | - | - |
Safe
|
Cisco Search vendor "Cisco" | Ios Search vendor "Cisco" for product "Ios" | 17.3.1 Search vendor "Cisco" for product "Ios" and version "17.3.1" | - |
Affected
| in | Cisco Search vendor "Cisco" | 1100-lte Integrated Services Router Search vendor "Cisco" for product "1100-lte Integrated Services Router" | - | - |
Safe
|
Cisco Search vendor "Cisco" | Ios Search vendor "Cisco" for product "Ios" | 17.3.1 Search vendor "Cisco" for product "Ios" and version "17.3.1" | - |
Affected
| in | Cisco Search vendor "Cisco" | 1101 Integrated Services Router Search vendor "Cisco" for product "1101 Integrated Services Router" | - | - |
Safe
|
Cisco Search vendor "Cisco" | Ios Search vendor "Cisco" for product "Ios" | 17.3.1 Search vendor "Cisco" for product "Ios" and version "17.3.1" | - |
Affected
| in | Cisco Search vendor "Cisco" | 1109 Integrated Services Router Search vendor "Cisco" for product "1109 Integrated Services Router" | - | - |
Safe
|
Cisco Search vendor "Cisco" | Ios Search vendor "Cisco" for product "Ios" | 17.3.1 Search vendor "Cisco" for product "Ios" and version "17.3.1" | - |
Affected
| in | Cisco Search vendor "Cisco" | 1111x Integrated Services Router Search vendor "Cisco" for product "1111x Integrated Services Router" | - | - |
Safe
|
Cisco Search vendor "Cisco" | Ios Search vendor "Cisco" for product "Ios" | 17.3.1 Search vendor "Cisco" for product "Ios" and version "17.3.1" | - |
Affected
| in | Cisco Search vendor "Cisco" | 111x Integrated Services Router Search vendor "Cisco" for product "111x Integrated Services Router" | - | - |
Safe
|
Cisco Search vendor "Cisco" | Ios Search vendor "Cisco" for product "Ios" | 17.3.1 Search vendor "Cisco" for product "Ios" and version "17.3.1" | - |
Affected
| in | Cisco Search vendor "Cisco" | 1120 Integrated Services Router Search vendor "Cisco" for product "1120 Integrated Services Router" | - | - |
Safe
|
Cisco Search vendor "Cisco" | Ios Search vendor "Cisco" for product "Ios" | 17.3.1 Search vendor "Cisco" for product "Ios" and version "17.3.1" | - |
Affected
| in | Cisco Search vendor "Cisco" | 1160 Integrated Services Router Search vendor "Cisco" for product "1160 Integrated Services Router" | - | - |
Safe
|
Cisco Search vendor "Cisco" | Ios Search vendor "Cisco" for product "Ios" | 17.3.1 Search vendor "Cisco" for product "Ios" and version "17.3.1" | - |
Affected
| in | Cisco Search vendor "Cisco" | 4221 Integrated Services Router Search vendor "Cisco" for product "4221 Integrated Services Router" | - | - |
Safe
|
Cisco Search vendor "Cisco" | Ios Search vendor "Cisco" for product "Ios" | 17.3.1 Search vendor "Cisco" for product "Ios" and version "17.3.1" | - |
Affected
| in | Cisco Search vendor "Cisco" | 4331 Integrated Services Router Search vendor "Cisco" for product "4331 Integrated Services Router" | - | - |
Safe
|
Cisco Search vendor "Cisco" | Ios Search vendor "Cisco" for product "Ios" | 17.3.1 Search vendor "Cisco" for product "Ios" and version "17.3.1" | - |
Affected
| in | Cisco Search vendor "Cisco" | 4431 Integrated Services Router Search vendor "Cisco" for product "4431 Integrated Services Router" | - | - |
Safe
|
Cisco Search vendor "Cisco" | Ios Search vendor "Cisco" for product "Ios" | 17.3.1 Search vendor "Cisco" for product "Ios" and version "17.3.1" | - |
Affected
| in | Cisco Search vendor "Cisco" | 4461 Integrated Services Router Search vendor "Cisco" for product "4461 Integrated Services Router" | - | - |
Safe
|
Cisco Search vendor "Cisco" | Ios Search vendor "Cisco" for product "Ios" | 17.3.1 Search vendor "Cisco" for product "Ios" and version "17.3.1" | - |
Affected
| in | Cisco Search vendor "Cisco" | Csr1000v Search vendor "Cisco" for product "Csr1000v" | - | - |
Safe
|
Cisco Search vendor "Cisco" | Ios Search vendor "Cisco" for product "Ios" | 17.3.1 Search vendor "Cisco" for product "Ios" and version "17.3.1" | - |
Affected
| in | Cisco Search vendor "Cisco" | Isa-3000-2c2f-k9 Search vendor "Cisco" for product "Isa-3000-2c2f-k9" | - | - |
Safe
|
Cisco Search vendor "Cisco" | Ios Search vendor "Cisco" for product "Ios" | 17.3.1 Search vendor "Cisco" for product "Ios" and version "17.3.1" | - |
Affected
| in | Cisco Search vendor "Cisco" | Isa-3000-4c-k9 Search vendor "Cisco" for product "Isa-3000-4c-k9" | - | - |
Safe
|
Cisco Search vendor "Cisco" | Firepower Management Center Search vendor "Cisco" for product "Firepower Management Center" | 2.9.14.4 Search vendor "Cisco" for product "Firepower Management Center" and version "2.9.14.4" | - |
Affected
| ||||||
Cisco Search vendor "Cisco" | Firepower Management Center Search vendor "Cisco" for product "Firepower Management Center" | 2.9.15 Search vendor "Cisco" for product "Firepower Management Center" and version "2.9.15" | - |
Affected
| ||||||
Cisco Search vendor "Cisco" | Firepower Management Center Search vendor "Cisco" for product "Firepower Management Center" | 2.9.16 Search vendor "Cisco" for product "Firepower Management Center" and version "2.9.16" | - |
Affected
| ||||||
Cisco Search vendor "Cisco" | Firepower Threat Defense Search vendor "Cisco" for product "Firepower Threat Defense" | < 6.6.0 Search vendor "Cisco" for product "Firepower Threat Defense" and version " < 6.6.0" | - |
Affected
|