TROYANOSYVIRUS
Volver a CVEs

CVE-2024-20342

MEDIUM
5.8

Descripcion

Multiple Cisco products are affected by a vulnerability in the rate filtering feature of the Snort detection engine that could allow an unauthenticated, remote attacker to bypass a configured rate limiting filter.  This vulnerability is due to an incorrect connection count comparison. An attacker could exploit this vulnerability by sending traffic through an affected device at a rate that exceeds a configured rate filter. A successful exploit could allow the attacker to successfully bypass the rate filter. This could allow unintended traffic to enter the network protected by the affected device.

Detalles CVE

Puntuacion CVSS v3.15.8
SeveridadMEDIUM
Vector CVSSCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:L
Vector de ataqueNETWORK
ComplejidadLOW
Privilegios requeridosNONE
Interaccion usuarioNONE
Publicado10/23/2024
Ultima modificacion8/11/2025
Fuentenvd
Avistamientos honeypot0

Productos afectados

cisco:firepower_threat_defense_softwarecisco:snort

Debilidades (CWE)

CWE-1025

Correlaciones IOC

Sin correlaciones registradas

This product uses data from the NVD API but is not endorsed or certified by the NVD.