Improper access control in Cisco AsyncOS for Secure Web Appliance - CVE-2023-20215
Published: August 3, 2023
Cisco AsyncOS for Secure Web Appliance
Cisco Systems, Inc
Description
The vulnerability allows a remote attacker to gain unauthorized access to otherwise restricted functionality.
The vulnerability exists due to improper detection of malicious traffic when the traffic is encoded with a specific content format. A remote attacker can bypass an explicit block rule and receive traffic that should have been rejected by the device.