Unknown
CVE-2023-20215
CVE ID
AttackerKB requires a CVE ID in order to pull vulnerability data and references from the CVE list and the National Vulnerability Database. If available, please supply below:
Add References:
CVE-2023-20215
MITRE ATT&CK
Collection
Command and Control
Credential Access
Defense Evasion
Discovery
Execution
Exfiltration
Impact
Initial Access
Lateral Movement
Persistence
Privilege Escalation
Topic Tags
Description
A vulnerability in the scanning engines of Cisco AsyncOS Software for Cisco Secure Web Appliance could allow an unauthenticated, remote attacker to bypass a configured rule, allowing traffic onto a network that should have been blocked.
This vulnerability is due to improper detection of malicious traffic when the traffic is encoded with a specific content format. An attacker could exploit this vulnerability by using an affected device to connect to a malicious server and receiving crafted HTTP responses. A successful exploit could allow the attacker to bypass an explicit block rule and receive traffic that should have been rejected by the device.
Add Assessment
No one has assessed this topic. Be the first to add your voice to the community.
CVSS V3 Severity and Metrics
General Information
Vendors
Products
- asyncos 11.7.0-406,
- asyncos 11.7.0-418,
- asyncos 11.7.1-006,
- asyncos 11.7.1-020,
- asyncos 11.7.1-049,
- asyncos 11.7.2-011,
- asyncos 11.8.0-414,
- asyncos 11.8.1-023,
- asyncos 11.8.3-018,
- asyncos 11.8.3-021,
- asyncos 12.0.1-268,
- asyncos 12.0.3-007,
- asyncos 12.5.1-011,
- asyncos 12.5.2-007,
- asyncos 12.5.4-005,
- asyncos 12.5.5-004,
- asyncos 14.0.2-012,
- asyncos 14.0.3-014,
- asyncos 14.0.4-005,
- asyncos 14.5.0-498,
- asyncos 14.5.1-008,
- asyncos 14.5.1-016
References
Additional Info
Technical Analysis
Report as Emergent Threat Response
Report as Zero-day Exploit
Report as Exploited in the Wild
CVE ID
AttackerKB requires a CVE ID in order to pull vulnerability data and references from the CVE list and the National Vulnerability Database. If available, please supply below: