CVE-2023-20177 is a medium-severity vulnerability affecting Cisco Firepower Threat Defense (FTD) Software. It allows an unauthenticated, remote attacker to cause the Snort 3 detection engine to unexpectedly restart due to a logic error during SSL/TLS connection inspection when URL Categories are configured. This can lead to a bypass or denial of service, with the engine restarting automatically. The vulnerability has a CVSS score of 4.0 (Medium), indicating a network attack vector with high attack complexity and low impact on availability, with no impact on confidentiality or integrity. There is no evidence of active exploitation, and no public exploit code (Metasploit, Nuclei, ExploitDB) is available. Despite the lack of active exploitation, the vulnerability has garnered some community attention, with one mention in discussions and one article covering it. Its EPSS score is very low, suggesting a minimal likelihood of exploitation in the wild.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
7.0.0CPE matchmatch criteria | cpe:2.3:a:cisco:firepower_threat_defense:7.0.0:*:*:*:*:*:*:* | ||
7.0.0.1CPE matchmatch criteria | cpe:2.3:a:cisco:firepower_threat_defense:7.0.0.1:*:*:*:*:*:*:* | ||
7.0.1CPE matchmatch criteria | cpe:2.3:a:cisco:firepower_threat_defense:7.0.1:*:*:*:*:*:*:* | ||
7.0.1.1CPE matchmatch criteria | cpe:2.3:a:cisco:firepower_threat_defense:7.0.1.1:*:*:*:*:*:*:* | ||
7.0.2CPE matchmatch criteria | cpe:2.3:a:cisco:firepower_threat_defense:7.0.2:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:N/I:N/A:L
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.