5.8
CVE-2024-20384
- EPSS 0.13%
- Veröffentlicht 23.10.2024 18:15:07
- Zuletzt bearbeitet 01.08.2025 16:02:16
- Quelle psirt@cisco.com
- CVE-Watchlists
- Unerledigt
A vulnerability in the Network Service Group (NSG) feature of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to bypass a configured access control list (ACL) and allow traffic that should be denied to flow through an affected device. This vulnerability is due to a logic error that occurs when NSG ACLs are populated on an affected device. An attacker could exploit this vulnerability by establishing a connection to the affected device. A successful exploit could allow the attacker to bypass configured ACL rules.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Cisco ≫ Adaptive Security Appliance Software Version9.16.1
Cisco ≫ Adaptive Security Appliance Software Version9.16.1.28
Cisco ≫ Adaptive Security Appliance Software Version9.16.2
Cisco ≫ Adaptive Security Appliance Software Version9.16.2.3
Cisco ≫ Adaptive Security Appliance Software Version9.16.2.7
Cisco ≫ Adaptive Security Appliance Software Version9.16.2.11
Cisco ≫ Adaptive Security Appliance Software Version9.16.2.13
Cisco ≫ Adaptive Security Appliance Software Version9.16.2.14
Cisco ≫ Adaptive Security Appliance Software Version9.16.3
Cisco ≫ Adaptive Security Appliance Software Version9.16.3.3
Cisco ≫ Adaptive Security Appliance Software Version9.16.3.14
Cisco ≫ Adaptive Security Appliance Software Version9.16.3.15
Cisco ≫ Adaptive Security Appliance Software Version9.16.3.19
Cisco ≫ Adaptive Security Appliance Software Version9.16.3.23
Cisco ≫ Adaptive Security Appliance Software Version9.16.4
Cisco ≫ Adaptive Security Appliance Software Version9.16.4.9
Cisco ≫ Adaptive Security Appliance Software Version9.16.4.14
Cisco ≫ Adaptive Security Appliance Software Version9.16.4.18
Cisco ≫ Adaptive Security Appliance Software Version9.16.4.19
Cisco ≫ Adaptive Security Appliance Software Version9.16.4.27
Cisco ≫ Adaptive Security Appliance Software Version9.16.4.38
Cisco ≫ Adaptive Security Appliance Software Version9.16.4.39
Cisco ≫ Adaptive Security Appliance Software Version9.16.4.42
Cisco ≫ Adaptive Security Appliance Software Version9.16.4.48
Cisco ≫ Adaptive Security Appliance Software Version9.16.4.55
Cisco ≫ Adaptive Security Appliance Software Version9.16.4.57
Cisco ≫ Adaptive Security Appliance Software Version9.16.4.61
Cisco ≫ Adaptive Security Appliance Software Version9.17.1
Cisco ≫ Adaptive Security Appliance Software Version9.17.1.7
Cisco ≫ Adaptive Security Appliance Software Version9.17.1.9
Cisco ≫ Adaptive Security Appliance Software Version9.17.1.10
Cisco ≫ Adaptive Security Appliance Software Version9.17.1.11
Cisco ≫ Adaptive Security Appliance Software Version9.17.1.13
Cisco ≫ Adaptive Security Appliance Software Version9.17.1.15
Cisco ≫ Adaptive Security Appliance Software Version9.17.1.20
Cisco ≫ Adaptive Security Appliance Software Version9.17.1.30
Cisco ≫ Adaptive Security Appliance Software Version9.17.1.33
Cisco ≫ Adaptive Security Appliance Software Version9.17.1.39
Cisco ≫ Adaptive Security Appliance Software Version9.18.1
Cisco ≫ Adaptive Security Appliance Software Version9.18.1.3
Cisco ≫ Adaptive Security Appliance Software Version9.18.2
Cisco ≫ Adaptive Security Appliance Software Version9.18.2.5
Cisco ≫ Adaptive Security Appliance Software Version9.18.2.7
Cisco ≫ Adaptive Security Appliance Software Version9.18.2.8
Cisco ≫ Adaptive Security Appliance Software Version9.18.3
Cisco ≫ Adaptive Security Appliance Software Version9.18.3.39
Cisco ≫ Adaptive Security Appliance Software Version9.18.3.46
Cisco ≫ Adaptive Security Appliance Software Version9.18.3.53
Cisco ≫ Adaptive Security Appliance Software Version9.18.3.55
Cisco ≫ Adaptive Security Appliance Software Version9.18.3.56
Cisco ≫ Adaptive Security Appliance Software Version9.18.4
Cisco ≫ Adaptive Security Appliance Software Version9.18.4.5
Cisco ≫ Adaptive Security Appliance Software Version9.18.4.8
Cisco ≫ Adaptive Security Appliance Software Version9.18.4.22
Cisco ≫ Adaptive Security Appliance Software Version9.18.4.24
Cisco ≫ Adaptive Security Appliance Software Version9.18.4.29
Cisco ≫ Adaptive Security Appliance Software Version9.19.1
Cisco ≫ Adaptive Security Appliance Software Version9.19.1.5
Cisco ≫ Adaptive Security Appliance Software Version9.19.1.9
Cisco ≫ Adaptive Security Appliance Software Version9.19.1.12
Cisco ≫ Adaptive Security Appliance Software Version9.19.1.18
Cisco ≫ Adaptive Security Appliance Software Version9.19.1.22
Cisco ≫ Adaptive Security Appliance Software Version9.19.1.24
Cisco ≫ Adaptive Security Appliance Software Version9.19.1.27
Cisco ≫ Adaptive Security Appliance Software Version9.19.1.28
Cisco ≫ Adaptive Security Appliance Software Version9.19.1.31
Cisco ≫ Adaptive Security Appliance Software Version9.20.1
Cisco ≫ Adaptive Security Appliance Software Version9.20.1.5
Cisco ≫ Adaptive Security Appliance Software Version9.20.2
Cisco ≫ Adaptive Security Appliance Software Version9.20.2.10
Cisco ≫ Adaptive Security Appliance Software Version9.20.2.21
Cisco ≫ Adaptive Security Appliance Software Version9.20.2.22
Cisco ≫ Firepower Threat Defense Version7.0.0
Cisco ≫ Firepower Threat Defense Version7.0.0.1
Cisco ≫ Firepower Threat Defense Version7.0.1
Cisco ≫ Firepower Threat Defense Version7.0.1.1
Cisco ≫ Firepower Threat Defense Version7.0.2
Cisco ≫ Firepower Threat Defense Version7.0.2.1
Cisco ≫ Firepower Threat Defense Version7.0.3
Cisco ≫ Firepower Threat Defense Version7.0.4
Cisco ≫ Firepower Threat Defense Version7.0.5
Cisco ≫ Firepower Threat Defense Version7.0.6
Cisco ≫ Firepower Threat Defense Version7.0.6.1
Cisco ≫ Firepower Threat Defense Version7.0.6.2
Cisco ≫ Firepower Threat Defense Version7.1.0
Cisco ≫ Firepower Threat Defense Version7.1.0.1
Cisco ≫ Firepower Threat Defense Version7.1.0.2
Cisco ≫ Firepower Threat Defense Version7.1.0.3
Cisco ≫ Firepower Threat Defense Version7.2.0
Cisco ≫ Firepower Threat Defense Version7.2.0.1
Cisco ≫ Firepower Threat Defense Version7.2.1
Cisco ≫ Firepower Threat Defense Version7.2.2
Cisco ≫ Firepower Threat Defense Version7.2.3
Cisco ≫ Firepower Threat Defense Version7.2.4
Cisco ≫ Firepower Threat Defense Version7.2.4.1
Cisco ≫ Firepower Threat Defense Version7.2.5
Cisco ≫ Firepower Threat Defense Version7.2.5.1
Cisco ≫ Firepower Threat Defense Version7.2.5.2
Cisco ≫ Firepower Threat Defense Version7.2.6
Cisco ≫ Firepower Threat Defense Version7.2.7
Cisco ≫ Firepower Threat Defense Version7.2.8
Cisco ≫ Firepower Threat Defense Version7.2.8.1
Cisco ≫ Firepower Threat Defense Version7.3.0
Cisco ≫ Firepower Threat Defense Version7.3.1
Cisco ≫ Firepower Threat Defense Version7.3.1.1
Cisco ≫ Firepower Threat Defense Version7.3.1.2
Cisco ≫ Firepower Threat Defense Version7.4.0
Cisco ≫ Firepower Threat Defense Version7.4.1
Cisco ≫ Firepower Threat Defense Version7.4.1.1
Cisco ≫ Firepower Threat Defense Version7.4.2
VulnDex Vulnerability Enrichment
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.13% | 0.328 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| psirt@cisco.com | 5.8 | 3.9 | 1.4 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:L/A:N
|
CWE-290 Authentication Bypass by Spoofing
This attack-focused weakness is caused by incorrectly implemented authentication schemes that are subject to spoofing attacks.