Cisco Firepower Threat Defense(FTD)是美国思科(Cisco)公司的一套提供下一代防火墙服务的统一软件。 Cisco Adaptive Security Appliance Software和Firepower Threat Defense Software存在安全漏洞,该漏洞源于远程访问VPN功能与HTTPS管理和站点到站点VPN功能之间的身份验证、授权和计费分离不当,可能允许未经身份验证的远程攻击者进行暴力攻击,试图识别有效的用户名和密码组合。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Cisco | Cisco Adaptive Security Appliance (ASA) Software | 9.8.1 |
affected |
9.8.1.5 |
affected | ||
9.8.1.7 |
affected | ||
9.8.2 |
affected | ||
9.8.2.8 |
affected | ||
9.8.2.14 |
affected | ||
9.8.2.15 |
affected | ||
9.8.2.17 |
affected | ||
| … +162 more rows | |||
| Cisco | Cisco Firepower Threat Defense Software | 6.2.3 |
affected |
6.2.3.1 |
affected | ||
6.2.3.2 |
affected | ||
6.2.3.3 |
affected | ||
6.2.3.4 |
affected | ||
6.2.3.5 |
affected | ||
6.2.3.6 |
affected | ||
6.2.3.7 |
affected | ||
| … +68 more rows | |||
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
10-question deep dive: root cause, exploitation, mitigation, urgency. Read summary free, full version requires login.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Cisco | Cisco Adaptive Security Appliance (ASA) Software | 9.8.1 | - |
|
| Cisco | Cisco Firepower Threat Defense Software | 6.2.3 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2023-20238 | 10.0 CRITICAL | Cisco BroadWorks Application 安全漏洞 |
| CVE-2023-20243 | 8.6 HIGH | Cisco Identity Services Engine 安全漏洞 |
| CVE-2023-20250 | 6.5 MEDIUM | Cisco Small Business 缓冲区错误漏洞 |
| CVE-2023-20263 | 4.7 MEDIUM | Cisco HyperFlex HX Data Platform 输入验证错误漏洞 |
No comments yet