CVE-2023-20267: Medium severity Cisco Secure Firewall Threat Defense vulnerability
A vulnerability in the IP geolocation rules of Snort 3 could allow an unauthenticated, remote attacker to potentially bypass IP address restrictions. This vulnerability exists because the configuration for IP geolocation rules is not parsed properly. An attacker could exploit this vulnerability by spoofing an IP address until they bypass the restriction. A successful exploit could allow the attacker to bypass location-based IP address restrictions.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Compensating control
Mitigate the risk by preventing IP spoofing so that location-based IP geolocation restrictions cannot be bypassed (e.g., deploy anti-spoofing filtering at the network edge/ingress such as BCP38-style source-address validation).
Event History
Frequently Asked Questions
What is the vulnerability ID for this Snort 3 vulnerability?
The vulnerability ID for this Snort 3 vulnerability is CVE-2023-20267.
What is the severity of CVE-2023-20267?
The severity of CVE-2023-20267 is medium (5.3).
What software is affected by CVE-2023-20267?
The Cisco Firepower Threat Defense software versions 6.7.0 to 7.3.1.1 are affected by CVE-2023-20267.
How can an attacker exploit CVE-2023-20267?
An attacker can exploit CVE-2023-20267 by bypassing IP address restrictions through the improper parsing of IP geolocation rules in Snort 3.
Where can I find more information about CVE-2023-20267?
You can find more information about CVE-2023-20267 at the Cisco Security Advisory: [link](https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ftdsnort3sip-bypass-LMz2ThKn).