Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2023-20267


A vulnerability in the IP geolocation rules of Snort 3 could allow an unauthenticated, remote attacker to potentially bypass IP address restrictions. This vulnerability exists because the configuration for IP geolocation rules is not parsed properly. An attacker could exploit this vulnerability by spoofing an IP address until they bypass the restriction. A successful exploit could allow the attacker to bypass location-based IP address restrictions.


Published

2023-11-01T18:15:09.810

Last Modified

2024-11-21T07:41:02.150

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 4.0 (MEDIUM)

Weaknesses
  • Type: Secondary
    CWE-284
  • Type: Primary
    NVD-CWE-noinfo

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application cisco firepower_threat_defense ≤ 7.3.1.1 Yes

References