← volver
CVE-2024-20363

CVE-2024-20363

CVSS 5.8 MEDIUMEPSS 0.4%CWE-290
Vexday Risk Score
13Bajo
Decisión SSVC (CISA)
Track
Sin señal de explotación → monitorear
CVSS 5.8EPSS 0.4%KEV nãoPoC Nuclei Metasploit Patch
Ciclo de vida
22 may 2024Publicada en NVD
Recomendación: Monitorear — sin señal de explotación por ahora.
Multiple Cisco products are affected by a vulnerability in the Snort Intrusion Prevention System (IPS) rule engine that could allow an unauthenticated, remote attacker to bypass the configured rules on an affected system. This vulnerability is due to incorrect HTTP packet handling. An attacker could exploit this vulnerability by sending crafted HTTP packets through an affected device. A successful exploit could allow the attacker to bypass configured IPS rules and allow uninspected traffic onto the network.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:L/A:N

¿Quieres saber si tu infraestructura está expuesta a esto?

Hablar con TrueHacking →