CVE-2024-20363
Summary
| CVE | CVE-2024-20363 |
|---|---|
| State | PUBLISHED |
| Assigner | cisco |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2024-05-22 17:16:13 UTC |
| Updated | 2026-08-11 19:33:44 UTC |
| Description | Multiple Cisco products are affected by a vulnerability in the Snort Intrusion Prevention System (IPS) rule engine that could allow an unauthenticated, remote attacker to bypass the configured rules on an affected system. This vulnerability is due to incorrect HTTP packet handling. An attacker could exploit this vulnerability by sending crafted HTTP packets through an affected device. A successful exploit could allow the attacker to bypass configured IPS rules and allow uninspected traffic onto the network. |
Risk And Classification
Primary CVSS: v3.1 5.8 MEDIUM from [email protected]
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:L/A:N
EPSS: 0.003660000 probability, percentile 0.294940000 (date 2026-08-12)
Problem Types: CWE-290 | CWE-290 Authentication Bypass by Spoofing | CWE-290 CWE-290 Authentication Bypass by Spoofing
| Version | Source | Type | Score | Severity | Vector |
|---|---|---|---|---|---|
| 3.1 | [email protected] | Secondary | 5.8 | MEDIUM | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:L/A:N |
| 3.1 | CNA | CVSSV3_1 | 5.8 | MEDIUM | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:L/A:N |
CVSS v3.1 Breakdown
Attack Vector
NetworkAttack Complexity
LowPrivileges Required
NoneUser Interaction
NoneScope
ChangedConfidentiality
NoneIntegrity
LowAvailability
NoneCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:L/A:N
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Cisco | Secure Firewall Threat Defense | 7.4.0 | All | All | All |
| Application | Cisco | Snort | All | All | All | All |
| Operating System | Cisco | Unified Threat Defense Snort Intrusion Prevention System Engine | 17.12.1a | All | All | All |
| Operating System | Cisco | Unified Threat Defense Snort Intrusion Prevention System Engine | 17.12.2 | All | All | All |
| Operating System | Cisco | Unified Threat Defense Snort Intrusion Prevention System Engine | 17.6.4 | All | All | All |
| Operating System | Cisco | Unified Threat Defense Snort Intrusion Prevention System Engine | 17.6.5 | All | All | All |
Vendor Declared Affected Products
| Source | Vendor | Product | Version | Platforms |
|---|---|---|---|---|
| CNA | Cisco | Cisco Firepower Threat Defense Software | affected 7.4.0 | Not specified |
| CNA | Cisco | Cisco UTD SNORT IPS Engine Software | affected 17.6.4 | Not specified |
| CNA | Cisco | Cisco UTD SNORT IPS Engine Software | affected 17.6.5 | Not specified |
| CNA | Cisco | Cisco UTD SNORT IPS Engine Software | affected 17.12.1a | Not specified |
| CNA | Cisco | Cisco UTD SNORT IPS Engine Software | affected 17.12.2 | Not specified |
| ADP | Cisco | Firepower Threat Defense | affected 7.4.0 | Not specified |
| ADP | Cisco | Snort Intrusion Prevention System | affected 17.6.4 | Not specified |
| ADP | Cisco | Snort Intrusion Prevention System | affected 17.6.5 | Not specified |
| ADP | Cisco | Snort Intrusion Prevention System | affected 17.12.1a | Not specified |
| ADP | Cisco | Snort Intrusion Prevention System | affected 17.12.2 | Not specified |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-snort3... | af854a3a-2127-422b-91ae-364da2661108 | sec.cloudapps.cisco.com | Vendor Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
Additional Advisory Data
Exploits
CNA: The Cisco PSIRT is not aware of any public announcements or malicious use of the vulnerability that is described in this advisory.
There are currently no legacy QID mappings associated with this CVE.