SB2024052721 - Improper access control in Cisco Firepower Threat Defense Software
Published: May 27, 2024
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Improper access control (CVE-ID: CVE-2024-20261)
The vulnerability allows a remote attacker to gain unauthorized access to otherwise restricted functionality.
The vulnerability exists due to a logic error when a specific class of encrypted archive files is inspected. A remote attacker can bypass a configured file policy to block an encrypted archive file.
Remediation
Install update from vendor's website.