Cisco Security Advisory 2024年07月05日
Cisco Firepower Threat Defense Software Encrypted Archive File Policy Bypass Vulnerability
index_new5.html
../../../zaker_core/zaker_tpl_static/wap/tpl_guoji1.html

 

思科Firepower Threat Defense(FTD)软件的文件政策功能存在漏洞,可能使未授权远程攻击者绕过配置的文件策略,发送可能含恶意软件的加密存档文件,思科已发布软件更新解决此问题。

🥔该漏洞存在于用于检查加密存档文件的文件政策功能中,是由于检查特定类加密存档文件时的逻辑错误导致的。攻击者可利用此漏洞,通过受影响设备发送特制的加密存档文件。

🚀成功利用此漏洞,攻击者可发送本应被思科FTD设备阻止和丢弃的、可能包含恶意软件的加密存档文件,带来安全风险。

🔧思科已发布软件更新来解决这一漏洞,但目前没有其他解决此漏洞的方法。此漏洞相关的咨询可在特定链接查看,且是思科相关软件安全咨询捆绑发布的一部分。

A vulnerability in the file policy feature that is used to inspect encrypted archive files of Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to bypass a configured file policy to block an encrypted archive file.

This vulnerability exists because of a logic error when a specific class of encrypted archive files is inspected. An attacker could exploit this vulnerability by sending a crafted, encrypted archive file through the affected device. A successful exploit could allow the attacker to send an encrypted archive file, which could contain malware and should have been blocked and dropped at the Cisco FTD device.

Cisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability.

This advisory is available at the following link:
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ftd-archive-bypass-z4wQjwcN

This advisory is part of the May 2024 release of the Cisco ASA, FMC, and FTD Software Security Advisory Bundled Publication. For a complete list of the advisories and links to them, see Cisco Event Response: May 2024 Semiannual Cisco ASA, FMC, and FTD Software Security Advisory Bundled Publication.


Security Impact Rating: Medium
CVE: CVE-2024-20261

Fish AI Reader

Fish AI Reader

AI辅助创作,多种专业模板,深度分析,高质量内容生成。从观点提取到深度思考,FishAI为您提供全方位的创作支持。新版本引入自定义参数,让您的创作更加个性化和精准。

FishAI

FishAI

鱼阅,AI 时代的下一个智能信息助手,助你摆脱信息焦虑

联系邮箱 441953276@qq.com

相关标签

思科FTD软件 文件策略漏洞 软件更新 安全风险
相关文章