Cisco Security Advisory 2024年07月05日
Cisco Firepower Management Center Software Object Group Access Control List Bypass Vulnerability
index_new5.html
../../../zaker_core/zaker_tpl_static/wap/tpl_guoji1.html

 

思科Firepower管理中心软件的访问控制列表功能存在漏洞,可能使未授权远程攻击者绕过配置的访问控制,该漏洞在高可用性设置中部署不当导致,思科已发布软件更新,此公告是2024年5月安全咨询的一部分。

🥅思科Firepower管理中心软件的访问控制列表功能的对象组存在漏洞,原因是在高可用性设置中从思科FMC软件到受管理的FTD设备的该功能部署不正确。此漏洞可能让未授权的远程攻击者绕过访问控制。

🚀在受影响设备部署访问控制列表的对象组并重启后,攻击者可利用此漏洞,通过受影响设备发送流量,从而成功绕过配置的访问控制,将流量发送到本应受保护的设备。

🔧思科已发布软件更新来解决此漏洞,但目前没有其他解决方法。此安全咨询公告是2024年5月思科ASA、FMC和FTD软件安全咨询捆绑发布的一部分,可通过链接查看详细信息。

A vulnerability in the Object Groups for Access Control Lists (ACLs) feature of Cisco Firepower Management Center (FMC) Software could allow an unauthenticated, remote attacker to bypass configured access controls on managed devices that are running Cisco Firepower Threat Defense (FTD) Software.

This vulnerability is due to the incorrect deployment of the Object Groups for ACLs feature from Cisco FMC Software to managed FTD devices in high-availability setups. After an affected device is rebooted following Object Groups for ACLs deployment, an attacker can exploit this vulnerability by sending traffic through the affected device. A successful exploit could allow the attacker to bypass configured access controls and successfully send traffic to devices that are expected to be protected by the affected device. 

Cisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability.

This advisory is available at the following link:
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-fmc-object-bypass-fTH8tDjq

This advisory is part of the May 2024 release of the Cisco ASA, FMC, and FTD Software Security Advisory Bundled Publication. For a complete list of the advisories and links to them, see Cisco Event Response: May 2024 Semiannual Cisco ASA, FMC, and FTD Software Security Advisory Bundled Publication.


Security Impact Rating: Medium
CVE: CVE-2024-20361

Fish AI Reader

Fish AI Reader

AI辅助创作,多种专业模板,深度分析,高质量内容生成。从观点提取到深度思考,FishAI为您提供全方位的创作支持。新版本引入自定义参数,让您的创作更加个性化和精准。

FishAI

FishAI

鱼阅,AI 时代的下一个智能信息助手,助你摆脱信息焦虑

联系邮箱 441953276@qq.com

相关标签

思科软件 漏洞 访问控制 软件更新
相关文章