Vulnslist

find the latest Cisco vulnerabilities

CVE-2024-20261

A vulnerability in the file policy feature that is used to inspect encrypted archive files of Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to bypass a configured file policy to block an encrypted archive file. This vulnerability exists because of a logic error when a specific class of encrypted archive files is inspected. An attacker could exploit this vulnerability by sending a crafted, encrypted archive file through the affected device. A successful exploit could allow the attacker to send an encrypted archive file, which could contain malware and should have been blocked and dropped at the Cisco FTD device.

SeverityMEDIUM
CVSS5.8
CWECWE-284
KEV
Published
Modified

Related Products

Product Advisory
Cisco Secure Firewall Threat Defense Virtual cisco-sa-ftd-archive-bypass-z4wQjwcN
Cisco Secure Firewall Threat Defense (FTD) Software cisco-sa-ftd-archive-bypass-z4wQjwcN
Cisco Secure Firewall 3100 Series cisco-sa-ftd-archive-bypass-z4wQjwcN
Cisco Firepower Threat Defense Software cisco-sa-ftd-archive-bypass-z4wQjwcN
Cisco Firepower 9000 Series cisco-sa-ftd-archive-bypass-z4wQjwcN
Cisco Firepower 4100 Series cisco-sa-ftd-archive-bypass-z4wQjwcN
Cisco Firepower 2100 Series cisco-sa-ftd-archive-bypass-z4wQjwcN
Cisco Firepower 1000 Series cisco-sa-ftd-archive-bypass-z4wQjwcN
Cisco ASA 5500-X Series Firewalls cisco-sa-ftd-archive-bypass-z4wQjwcN
Cisco 3000 Series Industrial Security Appliances (ISA) cisco-sa-ftd-archive-bypass-z4wQjwcN