CVE-2024-20384

A vulnerability in the Network Service Group (NSG) feature of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to bypass a configured access control list (ACL) and allow traffic that should be denied to flow through an affected device. This vulnerability is due to a logic error that occurs when NSG ACLs are populated on an affected device. An attacker could exploit this vulnerability by establishing a connection to the affected device. A successful exploit could allow the attacker to bypass configured ACL rules.
Configurations

No configuration.

History

25 Oct 2024, 12:56

Type Values Removed Values Added
Summary
  • (es) Una vulnerabilidad en la función Network Service Group (NSG) del software Cisco Adaptive Security Appliance (ASA) y del software Cisco Firepower Threat Defense (FTD) podría permitir que un atacante remoto no autenticado omita una lista de control de acceso (ACL) configurada y permita que el tráfico que debería estar denegado fluya a través de un dispositivo afectado. Esta vulnerabilidad se debe a un error lógico que ocurre cuando se completan las ACL de NSG en un dispositivo afectado. Un atacante podría aprovechar esta vulnerabilidad estableciendo una conexión con el dispositivo afectado. Una explotación exitosa podría permitir al atacante omitir las reglas de ACL configuradas.

23 Oct 2024, 18:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-10-23 18:15

Updated : 2024-10-25 12:56


NVD link : CVE-2024-20384

Mitre link : CVE-2024-20384

CVE.ORG link : CVE-2024-20384


JSON object : View

Products Affected

No product.

CWE
CWE-290

Authentication Bypass by Spoofing