VDB

CVE-2022-20730

CVE-2022-20730 PUBLISHED CVSS 4 MEDIUM

A vulnerability in the Security Intelligence feed feature of Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to bypass the Security Intelligence DNS feed. This vulnerability is due to incorrect feed update processing. An attacker could exploit this vulnerability by sending traffic through an affected device that should be blocked by the affected device. A successful exploit could allow the attacker to bypass device controls and successfully send traffic to devices that are expected to be protected by the affected device.

EPSS 0.99% · 61.2th percentile

Risk Scores

CVSS 3.1
4
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:N/I:L/A:N
EPSS Score
0.99%
61.2th percentile

Affected Products

VendorProductVersions
ciscofirepower_threat_defense0, 6.5.0, 6.7.0
CiscoCisco Firepower Threat Defense Softwaren/a

Timeline

  • Apr 27, 2022 CVE Published
  • May 3, 2022 EPSS Score
  • Jun 22, 2022 EPSS Score
  • Aug 12, 2022 EPSS Score
  • Oct 2, 2022 EPSS Score
  • Jan 10, 2023 EPSS Score
  • Mar 1, 2023 EPSS Score
  • Mar 7, 2023 EPSS Score
  • Apr 21, 2023 EPSS Score
  • Jun 10, 2023 EPSS Score
  • Jul 30, 2023 EPSS Score
  • Sep 18, 2023 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›