Know every vulnerabilitybefore it knows you.
DevGuard continuously monitors your dependencies and alerts you when CVEs like this one affect your stack — with real-time threat intelligence built for developers.
- Feiten
Cisco heeft kwetsbaarheden verholpen in ASA, Firepower en Snort.
- Interpretaties
Een kwaadwillende kan de kwetsbaarheden misbruiken om aanvallen uit te voeren die kunnen leiden tot de volgende categorieën schade:
- Denial-of-Service (DoS)
- Omzeilen van beveiligingsmaatregel
- (Remote) code execution (Gebruikersrechten)
- Verhoogde gebruikersrechten
- Oplossingen
Cisco heeft updates uitgebracht om de kwetsbaarheden te verhelpen in ASA, Firepower en Snort. Zie bijgevoegde referenties voor meer informatie:
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-asaftd-ogsnsg-aclbyp-3XB8q6jX
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-asaftd-saml-bypass-KkNvXyKW
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-fmc-object-bypass-fTH8tDjq
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-fmc-sqli-WFFDnNOs
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ftd-archive-bypass-z4wQjwcN
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-snort3-ips-bypass-uE69KBMd
- Kans
medium
- Schade
high
- CWE-264
CWE-264
- CWE-284
Improper Access Control
- CWE-290
Authentication Bypass by Spoofing
- CWE-436
Interpretation Conflict
- CWE-681
Incorrect Conversion between Numeric Types
- CWE-862
Missing Authorization
- CWE-89
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
Continuously monitor your dependencies and get alerted when vulnerabilities like this one affect your stack.
Checkout DevGuard