VDB

CVE-2022-20730

CVE-2022-20730 PUBLISHED CVSS 4 MEDIUM

A vulnerability in the Security Intelligence feed feature of Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to bypass the Security Intelligence DNS feed. This vulnerability is due to incorrect feed update processing. An attacker could exploit this vulnerability by sending traffic through an affected device that should be blocked by the affected device. A successful exploit could allow the attacker to bypass device controls and successfully send traffic to devices that are expected to be protected by the affected device.

EPSS 0.29% · 52.5th percentile

Risk Scores

CVSS 3.1
4
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:N/I:L/A:N
EPSS Score
0.29%
52.5th percentile

Affected Products

VendorProductVersions
ciscofirepower_threat_defense0, 6.5.0, 6.7.0
CiscoCisco Firepower Threat Defense Softwaren/a

Timeline

  • Apr 27, 2022 CVE Published
  • May 3, 2022 EPSS Score
  • Jun 22, 2022 EPSS Score
  • Aug 11, 2022 EPSS Score
  • Sep 30, 2022 EPSS Score
  • Nov 18, 2022 EPSS Score
  • Feb 25, 2023 EPSS Score
  • Mar 7, 2023 EPSS Score
  • Apr 16, 2023 EPSS Score
  • Jun 4, 2023 EPSS Score
  • Jul 24, 2023 EPSS Score
  • Sep 12, 2023 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›