PT-2023-4106 · Cisco · Cisco Secure Web Appliance+1

CVE-2023-20215

·

Publicado

2023-08-02

·

Atualizado

2024-01-25

CVSS v2.0

7.8

Alta

VetorAV:N/AC:L/Au:N/C:N/I:C/A:N
Name of the Vulnerable Software and Affected Versions Cisco Secure Web Appliance versions (affected versions not specified)
Description The issue is related to a flaw in the scanning mechanism of Cisco AsyncOS for Cisco Secure Web Appliance, specifically concerning inadequate access control. This flaw can be exploited by a remote attacker to bypass traffic block rules when certain encoding types, such as deflate, lzma, or brotli, are enabled. The vulnerability arises from improper detection of malicious traffic when it is encoded in a specific content format. An attacker could exploit this by using an affected device to connect to a malicious server and receive crafted HTTP responses, potentially allowing them to bypass explicit block rules and receive traffic that should have been rejected.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Improper Access Control

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2023-04415
CVE-2023-20215

Produtos afetados

Cisco Asyncos
Cisco Secure Web Appliance