Improper Handling of Unexpected Data Type in Cisco Firewall Threat Defense (FTD) - CVE-2022-20730
Published: April 28, 2022
Vulnerability identifier: #VU62684
CSH Severity: Low
CVSS v4: 6.3 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2022-20730
CWE-ID: CWE-241
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to bypass the Security Intelligence DNS feed.
The vulnerability exists due to incorrect feed update processing. A remote attacker can bypass device controls and send traffic to devices that are expected to be protected by the affected device.
Affected software
Cisco Firewall Threat Defense (FTD)
How to mitigate CVE-2022-20730
Install updates from vendor's website.
Cisco Firewall Threat Defense (FTD) - addressed in versions 6.4.0.15, 6.6.5.2, 7.0.2