First published: Wed Oct 23 2024(Updated: )
Multiple Cisco products are affected by a vulnerability in the rate filtering feature of the Snort detection engine that could allow an unauthenticated, remote attacker to bypass a configured rate limiting filter. This vulnerability is due to an incorrect connection count comparison. An attacker could exploit this vulnerability by sending traffic through an affected device at a rate that exceeds a configured rate filter. A successful exploit could allow the attacker to successfully bypass the rate filter. This could allow unintended traffic to enter the network protected by the affected device.Cisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability.This advisory is available at the following link:https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-snort-rf-bypass-OY8f3pnMThis advisory is part of the October 2024 release of the Cisco ASA, FMC, and FTD Software Security Advisory Bundled Publication. For a complete list of the advisories and links to them, see Cisco Event Response: October 2024 Semiannual Cisco ASA, FMC, and FTD Software Security Advisory Bundled Publication.
Affected Software | Affected Version | How to fix |
---|---|---|
Snort | ||
Cisco ASA Software | ||
Cisco FMC | ||
Cisco FTD Software Releases |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of cisco-sa-snort-rf-bypass-OY8f3pnM is considered high due to the potential for unauthenticated access to bypass rate limiting filters.
To fix cisco-sa-snort-rf-bypass-OY8f3pnM, ensure you update to the latest versions of affected Cisco products as provided by Cisco.
Products affected by cisco-sa-snort-rf-bypass-OY8f3pnM include Cisco Snort, Cisco ASA, Cisco FMC, and Cisco FTD.
Yes, cisco-sa-snort-rf-bypass-OY8f3pnM can be exploited remotely by unauthenticated attackers.
It is recommended to review configuration settings and apply patches immediately to mitigate the risks associated with cisco-sa-snort-rf-bypass-OY8f3pnM.