QID 317394

QID 317394: Cisco Firepower Threat Defense (FTD) Software FTP Inspection Bypass Vulnerability (cisco-sa-snort-ftd-zXYtnjOM, CSCwb69096)

Multiple Cisco products are affected by a vulnerability in the Snort detection engine that could allow an unauthenticated, remote attacker to bypass the configured policies on an affected system.

Affected Products
Vulnerable versions are referred from the BugID CSCwb69096

This vulnerability affects Cisco products if they are running a vulnerable release of Cisco FTD Software configured with snort version 3

Note: This QID is not checking for Snort 3 status. Hence QID is kept as practice

6.7 prior to 7.0.5
7.1 prior to 7.1.0.3
7.2 prior to 7.2.1

QID Detection Logic (Authenticated):
This QID will check the version retrieved via Unix Auth using "show version" command.

A successful exploit could allow the attacker to bypass FTP inspection and deliver a malicious payload.

  • CVSS V3 rated as Medium - 5.8 severity.
  • CVSS V2 rated as High - 7.8 severity.
  • Solution

    Customers are advised to refer to cisco-sa-snort-ftd-zXYtnjOM for more information.

    CVEs related to QID 317394

    Software Advisories
    Advisory ID Software Component Link
    cisco-sa-snort-ftd-zXYtnjOM URL Logo sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-snort-ftd-zXYtnjOM