CVE-2023-20215 is a medium-severity vulnerability affecting Cisco AsyncOS Software for Cisco Secure Web Appliance. It allows an unauthenticated, remote attacker to bypass configured blocking rules due to improper detection of malicious traffic encoded in a specific content format. Exploitation involves an affected device connecting to a malicious server and receiving crafted HTTP responses, leading to the reception of traffic that should have been blocked. There is no public exploit code available, no evidence of active exploitation, and minimal community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
11.7.0-406CPE matchmatch criteria | cpe:2.3:o:cisco:asyncos:11.7.0-406:*:*:*:*:*:*:* | ||
11.7.0-418CPE matchmatch criteria | cpe:2.3:o:cisco:asyncos:11.7.0-418:*:*:*:*:*:*:* | ||
11.7.1-006CPE matchmatch criteria | cpe:2.3:o:cisco:asyncos:11.7.1-006:*:*:*:*:*:*:* | ||
11.7.1-020CPE matchmatch criteria | cpe:2.3:o:cisco:asyncos:11.7.1-020:*:*:*:*:*:*:* | ||
11.7.1-049CPE matchmatch criteria | cpe:2.3:o:cisco:asyncos:11.7.1-049:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.