Multiple Cisco products are affected by a vulnerability in the Snort Intrusion Prevention System (IPS) rule engine that could allow an unauthenticated, remote attacker to bypass the configured rules on an affected system. This vulnerability is due to incorrect HTTP packet handling. An attacker could exploit this vulnerability by sending crafted HTTP packets through an affected device. A successful exploit could allow the attacker to bypass configured IPS rules and allow uninspected traffic onto the network.
Metrics
Affected Vendors & Products
References
History
Thu, 03 Jul 2025 17:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Cisco
Cisco firepower Threat Defense Cisco snort Cisco unified Threat Defense Snort Intrusion Prevention System Engine |
|
CPEs | cpe:2.3:a:cisco:firepower_threat_defense:7.4.0:*:*:*:*:*:*:* cpe:2.3:a:cisco:snort:*:*:*:*:*:*:*:* cpe:2.3:o:cisco:unified_threat_defense_snort_intrusion_prevention_system_engine:17.12.1a:*:*:*:*:*:*:* cpe:2.3:o:cisco:unified_threat_defense_snort_intrusion_prevention_system_engine:17.12.2:*:*:*:*:*:*:* cpe:2.3:o:cisco:unified_threat_defense_snort_intrusion_prevention_system_engine:17.6.4:*:*:*:*:*:*:* cpe:2.3:o:cisco:unified_threat_defense_snort_intrusion_prevention_system_engine:17.6.5:*:*:*:*:*:*:* |
|
Vendors & Products |
Cisco
Cisco firepower Threat Defense Cisco snort Cisco unified Threat Defense Snort Intrusion Prevention System Engine |

Status: PUBLISHED
Assigner: cisco
Published:
Updated: 2024-08-01T21:59:42.321Z
Reserved: 2023-11-08T15:08:07.651Z
Link: CVE-2024-20363

Updated: 2024-08-01T21:59:42.321Z

Status : Analyzed
Published: 2024-05-22T17:16:13.950
Modified: 2025-07-03T17:19:51.450
Link: CVE-2024-20363

No data.