QID 317393
QID 317393: Cisco Firepower Threat Defense (FTD) Software FTP Inspection Bypass Vulnerability (cisco-sa-snort-ftd-zXYtnjOM, CSCwd83613)
Multiple Cisco products are affected by a vulnerability in the Snort detection engine that could allow an unauthenticated, remote attacker to bypass the configured policies on an affected system.
Affected Products
Vulnerable versions are referred from the BugID CSCwd83613
This vulnerability affects Cisco products if they are running a vulnerable release of Cisco FTD Software configured with snort version 2
Note: This QID is not checking for Snort 2 status. Hence QID is kept as practice
Prior to 6.4.0.17
6.5 prior to 7.0.6
7.1 prior to 7.2.4
7.3 prior to 7.3.1.2
QID Detection Logic (Authenticated):
This QID will check the version retrieved via Unix Auth using "show version" command.
A successful exploit could allow the attacker to bypass FTP inspection and deliver a malicious payload.
Customers are advised to refer to cisco-sa-snort-ftd-zXYtnjOM for more information.
- cisco-sa-snort-ftd-zXYtnjOM -
sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-snort-ftd-zXYtnjOM
CVEs related to QID 317393
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| cisco-sa-snort-ftd-zXYtnjOM |
|