VDB
CVE-2022-20730
CVE-2022-20730
PUBLISHED
CVSS 4 MEDIUM
A vulnerability in the Security Intelligence feed feature of Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to bypass the Security Intelligence DNS feed. This vulnerability is due to incorrect feed update processing. An attacker could exploit this vulnerability by sending traffic through an affected device that should be blocked by the affected device. A successful exploit could allow the attacker to bypass device controls and successfully send traffic to devices that are expected to be protected by the affected device.
EPSS 0.29% · 52.5th percentile
Risk Scores
CVSS 3.1
4
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:N/I:L/A:N
EPSS Score
0.29%
52.5th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| cisco | firepower_threat_defense | 0, 6.5.0, 6.7.0 |
| Cisco | Cisco Firepower Threat Defense Software | n/a |
Exploit Intelligence
Timeline
- Apr 27, 2022 CVE Published
- May 3, 2022 EPSS Score
- Jun 22, 2022 EPSS Score
- Aug 11, 2022 EPSS Score
- Sep 30, 2022 EPSS Score
- Nov 18, 2022 EPSS Score
- Feb 25, 2023 EPSS Score
- Mar 7, 2023 EPSS Score
- Apr 16, 2023 EPSS Score
- Jun 4, 2023 EPSS Score
- Jul 24, 2023 EPSS Score
- Sep 12, 2023 EPSS Score