CVE-2024-20342
MEDIUMDescription
Multiple Cisco products are affected by a vulnerability in the rate filtering feature of the Snort detection engine that could allow an unauthenticated, remote attacker to bypass a configured rate limiting filter. This vulnerability is due to an incorrect connection count comparison. An attacker could exploit this vulnerability by sending traffic through an affected device at a rate that exceeds a configured rate filter. A successful exploit could allow the attacker to successfully bypass the rate filter. This could allow unintended traffic to enter the network protected by the affected device.
Is your site exposed to CVE-2024-20342?
Run a free security scan — no signup, results in seconds.
CVSS v3.1 Score
Weakness Type (CWE)
Affected Products
| Vendor | Product |
|---|---|
| cisco | snort |
| cisco | firepower_threat_defense_software |
| cisco | firepower_threat_defense_software |
| cisco | firepower_threat_defense_software |
| cisco | firepower_threat_defense_software |
| cisco | firepower_threat_defense_software |
References
Frequently Asked Questions
What is CVE-2024-20342? +
How severe is CVE-2024-20342? +
What products are affected by CVE-2024-20342? +
How do I check if I'm vulnerable to CVE-2024-20342? +
Related Vulnerabilities
In OpenStack Blazar before 17.0.1, the V2 lease API does not enforce object-level authorization on its update and delete operations …
The Rattadan Cosmowarp smart contract before 56c6147 can have a comparison to an unintended value of current_admin.
A logic flaw in Java cache key handling object comparison handling could lead to improper identifier resolution when processing specific …
stoatchat (delta) versions before 20250210-1 (0.8.2) contain a logic error in the query messages route. When fetching messages 'nearby' another …
Punk::Plugin::TOTP versions before 0.05 for Perl accept another account's recovery code at the two-factor challenge because totp_use_recovery compares user identifiers …
Misskey is an open source, federated social media platform. The patch for CVE-2024-52591 did not sufficiently validate the relation between …