Cyber Resilience

CVE-2023-20071

Cisco Firepower Threat Defense ≤ 6.4.0.17

Published
01 November 2023
Modified
21 November 2024
Patch / advisory
CVSS Score v3.1 5.8
Click a component to see what it means
Raw vectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:L/A:N
EPSS Score 0.0052 41th percentile
Risk Priority 35 floored blend · peak EPSS

Summary

CVE-2023-20071 is a medium-severity Inadequate Detection or Handling of Adversarial Input Perturbations in Automated Recognition Mechanism (CWE-1039) vulnerability in Cisco Firepower Threat Defense. Its CVSS base score is 5.8 (Medium).

Operationally, ranked at the 41th percentile by exploit likelihood (below the median); it is not currently listed in the CISA KEV catalog.

EU & UK References

Vulnerability Data

Multiple Cisco products are affected by a vulnerability in the Snort detection engine that could allow an unauthenticated, remote attacker to bypass the configured policies on an affected system. This vulnerability is due to a flaw in the FTP module…

more

of the Snort detection engine. An attacker could exploit this vulnerability by sending crafted FTP traffic through an affected device. A successful exploit could allow the attacker to bypass FTP inspection and deliver a malicious payload.

CWE(s)

Related Threats

CVEs Like This One

CVE-2023-20246Same product: Cisco Firepower Threat Defense
CVE-2023-20031Same product: Cisco Firepower Threat Defense
CVE-2023-20070Same product: Cisco Firepower Threat Defense
CVE-2024-20407Same product: Cisco Firepower Threat Defense
CVE-2024-20261Same product: Cisco Firepower Threat Defense
CVE-2023-20083Same product: Cisco Firepower Threat Defense
CVE-2023-20270Same product: Cisco Firepower Threat Defense
CVE-2023-20267Same product: Cisco Firepower Threat Defense
CVE-2024-20431Same product: Cisco Firepower Threat Defense
CVE-2023-20177Same product: Cisco Firepower Threat Defense

Affected Assets

cisco
firepower threat defense
≤ 6.4.0.17 · 6.5.0 — 7.0.6 · 7.1.0 — 7.2.4
cisco
cyber vision
≤ 4.1.3
cisco
unified threat defense
17.3 — 17.3.8 · 17.6 — 17.6.6 · 17.9 — 17.9.4
cisco
meraki mx security appliance firmware
all versions

Mitigating Controls

Mitigating Controls (NIST CSF 2.0) AI

Derived directly from the weakness types (CWEs) cited in the NVD entry via our AI-authored CWE→CSF cross-walk (authority under review) — links open the control.

DE.CM-09 mostly match
prevents

Monitoring runtime data and inputs directly supports detection of adversarial perturbations to recognition mechanisms.

PR.PS-06 mostly match
prevents

Secure SDLC practices include robustness testing and adversarial-input handling during model development.

ID.RA-01 partial match
prevents

Recording this class of ML vulnerability is a prerequisite for subsequent mitigation.

ID.RA-03 partial match
prevents

Explicit identification of adversarial ML threats informs the need to address this weakness.

Mitigating Controls (ISO/IEC 27001:2022 Annex A) AI

Derived directly from the weakness types (CWEs) cited in the NVD entry via our AI-authored CWE→ISO cross-walk (authority under review) — links open the control.

detects

Security testing in development can explicitly cover adversarial input testing for recognition mechanisms.

mitigates

Threat intelligence can surface adversarial ML attack patterns but does not implement technical controls.

prevents

Secure development lifecycle requires adversarial testing and robustness validation for ML-based recognition components.

prevents

Application security requirements can mandate detection and handling of adversarial perturbations in automated recognition systems.

prevents

Secure architecture principles include resilience against input manipulation and adversarial ML attacks.

prevents

Secure coding practices can incorporate input sanitization and adversarial robustness checks for ML models.

References