CVE-2023-20071
Cisco Firepower Threat Defense ≤ 6.4.0.17
Raw vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:L/A:NSummary
CVE-2023-20071 is a medium-severity Inadequate Detection or Handling of Adversarial Input Perturbations in Automated Recognition Mechanism (CWE-1039) vulnerability in Cisco Firepower Threat Defense. Its CVSS base score is 5.8 (Medium).
Operationally, ranked at the 41th percentile by exploit likelihood (below the median); it is not currently listed in the CISA KEV catalog.
EU & UK References
- 🇪🇺 ENISA EUVD: EUVD-2023-24250
Vulnerability Data
Multiple Cisco products are affected by a vulnerability in the Snort detection engine that could allow an unauthenticated, remote attacker to bypass the configured policies on an affected system. This vulnerability is due to a flaw in the FTP module…
more
of the Snort detection engine. An attacker could exploit this vulnerability by sending crafted FTP traffic through an affected device. A successful exploit could allow the attacker to bypass FTP inspection and deliver a malicious payload.
- CWE(s)
Related Threats
CVEs Like This One
Affected Assets
Mitigating Controls
Mitigating Controls (NIST CSF 2.0) AI
Derived directly from the weakness types (CWEs) cited in the NVD entry via our AI-authored CWE→CSF cross-walk (authority under review) — links open the control.
Monitoring runtime data and inputs directly supports detection of adversarial perturbations to recognition mechanisms.
Secure SDLC practices include robustness testing and adversarial-input handling during model development.
Recording this class of ML vulnerability is a prerequisite for subsequent mitigation.
Explicit identification of adversarial ML threats informs the need to address this weakness.
Mitigating Controls (ISO/IEC 27001:2022 Annex A) AI
Derived directly from the weakness types (CWEs) cited in the NVD entry via our AI-authored CWE→ISO cross-walk (authority under review) — links open the control.
Security testing in development can explicitly cover adversarial input testing for recognition mechanisms.
Threat intelligence can surface adversarial ML attack patterns but does not implement technical controls.
Secure development lifecycle requires adversarial testing and robustness validation for ML-based recognition components.
Application security requirements can mandate detection and handling of adversarial perturbations in automated recognition systems.
Secure architecture principles include resilience against input manipulation and adversarial ML attacks.
Secure coding practices can incorporate input sanitization and adversarial robustness checks for ML models.