QID 317399

QID 317399: Cisco Firepower Threat Defense (FTD) Software Snort 3 Snort 3 Access Control Policy Bypass Vulnerability (cisco-sa-ftd-snort3acp-bypass-3bdR2BEh)

This vulnerability is due to a logic error that occurs when the access control policies are being populated.

Affected Products
Vulnerable versions are referred from the BugID CSCwe15280

This vulnerability affects Cisco products if they are running a vulnerable release of Cisco FTD Software configured with snort version 3

Note: This QID is not checking for Snort 3 status. Hence QID is kept as practice

Affected Products
From 7.0.5 prior to 7.0.6
From 7.2.0 prior to 7.2.4

QID Detection Logic (Authenticated):
This QID will check the version retrieved via Unix Auth using show version command.

A successful exploit could allow the attacker to bypass configured access control rules on the affected system.

  • CVSS V3 rated as Medium - 5.8 severity.
  • CVSS V2 rated as Medium - 4 severity.
  • Solution

    Customers are advised to refer to cisco-sa-ftd-snort3acp-bypass-3bdR2BEh for more information.

    CVEs related to QID 317399

    Software Advisories
    Advisory ID Software Component Link
    cisco-sa-ftd-snort3acp-bypass-3bdR2BEh URL Logo sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ftd-snort3acp-bypass-3bdR2BEh