5.3
CVE-2020-3186
- EPSS 1.33%
- Veröffentlicht 06.05.2020 17:15:12
- Zuletzt bearbeitet 11.08.2026 19:33:44
- Erkennungen
Cisco Firepower Threat Defense Software Management Access List Bypass Vulnerability
A vulnerability in the management access list configuration of Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to bypass a configured management interface access list on an affected system. The vulnerability is due to the configuration of different management access lists, with ports allowed in one access list and denied in another. An attacker could exploit this vulnerability by sending crafted remote management traffic to the local IP address of an affected system. A successful exploit could allow the attacker to bypass the configured management access list policies, and traffic to the management interface would not be properly denied.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Cisco ≫ Secure Firewall Threat Defense Version >= 6.3.0 < 6.3.0.6
Cisco ≫ Secure Firewall Threat Defense Version >= 6.4.0 < 6.4.0.7
Cisco ≫ Secure Firewall Threat Defense Version >= 6.5.0 < 6.5.0.2
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 1.33% | 0.673 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 5.3 | 3.9 | 1.4 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
|
| NIST | 5 | 10 | 2.9 |
AV:N/AC:L/Au:N/C:N/I:P/A:N
|
| Cisco PSIRT | 5.3 | 3.9 | 1.4 |
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
|
CWE-284 Improper Access Control
The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ftd-accesslist-bypass-5dZs5qZp