CVE-2020-3186: Cisco Firepower Threat Defense Software Management Access List Bypass Vulnerability
A vulnerability in the management access list configuration of Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to bypass a configured management interface access list on an affected system. The vulnerability is due to the configuration of different management access lists, with ports allowed in one access list and denied in another. An attacker could exploit this vulnerability by sending crafted remote management traffic to the local IP address of an affected system. A successful exploit could allow the attacker to bypass the configured management access list policies, and traffic to the management interface would not be properly denied.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Compensating control
Mitigate by ensuring the management access list configuration consistently denies the affected management ports on all management access lists, preventing cases where ports are allowed in one list and denied in another on Cisco Firepower Threat Defense (FTD) Software.
Event History
Frequently Asked Questions
What is CVE-2020-3186?
CVE-2020-3186 is a vulnerability in the management access list configuration of Cisco Firepower Threat Defense (FTD) Software.
How does CVE-2020-3186 impact Cisco Firepower Threat Defense?
CVE-2020-3186 allows an unauthenticated, remote attacker to bypass a configured management interface access list on an affected system.
What is the severity of CVE-2020-3186?
The severity of CVE-2020-3186 is medium with a CVSS score of 5.3.
Which versions of Cisco Firepower Threat Defense are affected by CVE-2020-3186?
Version 6.3.0 to 6.3.0.6, 6.4.0 to 6.4.0.7, and 6.5.0 to 6.5.0.2 of Cisco Firepower Threat Defense are affected by CVE-2020-3186.
How can I learn more about CVE-2020-3186?
You can learn more about CVE-2020-3186 in the Cisco Security Advisory: [link](https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ftd-accesslist-bypass-5dZs5qZp).