Improper Handling of Unexpected Data Type in Cisco Firewall Threat Defense (FTD) - CVE-2022-20730

 

Improper Handling of Unexpected Data Type in Cisco Firewall Threat Defense (FTD) - CVE-2022-20730

Published: April 28, 2022


Vulnerability identifier: #VU62684
CSH Severity: Low
CVSS v4: 6.3 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2022-20730
CWE-ID: CWE-241
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to bypass the Security Intelligence DNS feed. 

The vulnerability exists due to incorrect feed update processing. A remote attacker can bypass device controls and send traffic to devices that are expected to be protected by the affected device. 


Affected software

Cisco Firewall Threat Defense (FTD)

How to mitigate CVE-2022-20730

Install updates from vendor's website.

Cisco Firewall Threat Defense (FTD) - addressed in versions 6.4.0.15, 6.6.5.2, 7.0.2

External References

Related Security Bulletins