MEDIUM✓ PATCH🇵🇱 Wersja polska

CVE-2024-20342

CVSS 5.8v3.1pub. 2024-10-23upd. 2026-08-11

Multiple Cisco products are affected by a vulnerability in the rate filtering feature of the Snort detection engine that could allow an unauthenticated, remote attacker to bypass a configured rate limiting filter.  This vulnerability is due to an incorrect connection count comparison. An attacker could exploit this vulnerability by sending traffic through an affected device at a rate that exceeds a configured rate filter. A successful exploit could allow the attacker to successfully bypass the rate filter. This could allow unintended traffic to enter the network protected by the affected device.

CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:L
  • Cisco Secure Firewall Threat Defense

    APP
    Cisco
    7.1.07.3.0< 7.0.6.27.2.0 – 7.2.6 (excl.)7.4.0 – 7.4.2 (excl.)
  • Cisco Snort

    APP
    Cisco
    3.0.0.0 – 3.1.74.0 (excl.)
🟢
PATCH AVAILABLE
Vendor update available. Deploy in standard maintenance cycle.
CWE
References

Related vulnerabilities

CVE-2025-20333CRITICAL9.9⚠ KEVPL ✓same product

RCE jako root w Cisco ASA i FTD poprzez podatny serwer VPN web

CVE-2025-20363CRITICAL9.0PL ✓same product

RCE w web services Cisco ASA, FTD, IOS, IOS XE, IOS XR przez HTTP

CVE-2024-20412CRITICAL9.3PL ✓same product

Cisco FTD: statyczne konta z zakodowanymi hasłami umożliwiają nieautoryzowany dostęp

CVE-2020-3187CRITICAL9.1PL ✓same product

Path Traversal w Cisco ASA i FTD — nieautoryzowany dostęp do plików przez WebVPN/AnyConnect

CVE-2018-0101CRITICAL10.0PL ✓same product

Cisco ASA SSL VPN — double free umożliwiający RCE lub DoS