Open-Source Security Intelligence

Know every vulnerability
before it knows you.

DevGuard continuously monitors your dependencies and alerts you when CVEs like this one affect your stack — with real-time threat intelligence built for developers.

Search

NCSC-2024-0233

Published May 23, 2024·Last modified May 23, 2024
Description
Feiten

Cisco heeft kwetsbaarheden verholpen in ASA, Firepower en Snort.

Interpretaties

Een kwaadwillende kan de kwetsbaarheden misbruiken om aanvallen uit te voeren die kunnen leiden tot de volgende categorieën schade:

  • Denial-of-Service (DoS)
  • Omzeilen van beveiligingsmaatregel
  • (Remote) code execution (Gebruikersrechten)
  • Verhoogde gebruikersrechten
Oplossingen

Cisco heeft updates uitgebracht om de kwetsbaarheden te verhelpen in ASA, Firepower en Snort. Zie bijgevoegde referenties voor meer informatie:

https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-asaftd-ogsnsg-aclbyp-3XB8q6jX

https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-asaftd-saml-bypass-KkNvXyKW

https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-fmc-object-bypass-fTH8tDjq

https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-fmc-sqli-WFFDnNOs

https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ftd-archive-bypass-z4wQjwcN

https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-snort3-ips-bypass-uE69KBMd

Kans

medium

Schade

high

CWE-264

CWE-264

CWE-284

Improper Access Control

CWE-290

Authentication Bypass by Spoofing

CWE-436

Interpretation Conflict

CWE-681

Incorrect Conversion between Numeric Types

CWE-862

Missing Authorization

CWE-89

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

Scan your project

Continuously monitor your dependencies and get alerted when vulnerabilities like this one affect your stack.

Checkout DevGuard