Multiple Cisco products are affected by a vulnerability in Snort access control policies that could allow an unauthenticated, remote attacker to bypass the configured policies on an affected system. This vulnerability is due to a logic error that occurs when the access control policies are being populated. An attacker could exploit this vulnerability by establishing a connection to an affected device. A successful exploit could allow the attacker to bypass configured access control rules on the affected system.
2023-11-01T18:15:09.583
2024-11-21T07:40:59.063
Modified
CVSSv3.1: 5.8 (MEDIUM)
| Type | Vendor | Product | Version/Range | Vulnerable? |
|---|---|---|---|---|
| Application | snort | snort | < 3.1.57.0 | Yes |
| Application | cisco | firepower_threat_defense | ≤ 7.3.1.1 | Yes |
| Operating System | cisco | ios_xe | < 17.12.2 | Yes |