VYPR
Medium severity5.8NVD Advisory· Published Aug 3, 2023· Updated Jun 17, 2026

CVE-2023-20215

CVE-2023-20215

Description

A vulnerability in the scanning engines of Cisco AsyncOS Software for Cisco Secure Web Appliance could allow an unauthenticated, remote attacker to bypass a configured rule, allowing traffic onto a network that should have been blocked. This vulnerability is due to improper detection of malicious traffic when the traffic is encoded with a specific content format. An attacker could exploit this vulnerability by using an affected device to connect to a malicious server and receiving crafted HTTP responses. A successful exploit could allow the attacker to bypass an explicit block rule and receive traffic that should have been rejected by the device.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

24
  • cpe:2.3:o:cisco:asyncos:11.7.0-406:*:*:*:*:*:*:*+ 21 more
    • cpe:2.3:o:cisco:asyncos:11.7.0-406:*:*:*:*:*:*:*
    • cpe:2.3:o:cisco:asyncos:11.7.0-418:*:*:*:*:*:*:*
    • cpe:2.3:o:cisco:asyncos:11.7.1-006:*:*:*:*:*:*:*
    • cpe:2.3:o:cisco:asyncos:11.7.1-020:*:*:*:*:*:*:*
    • cpe:2.3:o:cisco:asyncos:11.7.1-049:*:*:*:*:*:*:*
    • cpe:2.3:o:cisco:asyncos:11.7.2-011:*:*:*:*:*:*:*
    • cpe:2.3:o:cisco:asyncos:11.8.0-414:*:*:*:*:*:*:*
    • cpe:2.3:o:cisco:asyncos:11.8.1-023:*:*:*:*:*:*:*
    • cpe:2.3:o:cisco:asyncos:11.8.3-018:*:*:*:*:*:*:*
    • cpe:2.3:o:cisco:asyncos:11.8.3-021:*:*:*:*:*:*:*
    • cpe:2.3:o:cisco:asyncos:12.0.1-268:*:*:*:*:*:*:*
    • cpe:2.3:o:cisco:asyncos:12.0.3-007:*:*:*:*:*:*:*
    • cpe:2.3:o:cisco:asyncos:12.5.1-011:*:*:*:*:*:*:*
    • cpe:2.3:o:cisco:asyncos:12.5.2-007:*:*:*:*:*:*:*
    • cpe:2.3:o:cisco:asyncos:12.5.4-005:*:*:*:*:*:*:*
    • cpe:2.3:o:cisco:asyncos:12.5.5-004:*:*:*:*:*:*:*
    • cpe:2.3:o:cisco:asyncos:14.0.2-012:*:*:*:*:*:*:*
    • cpe:2.3:o:cisco:asyncos:14.0.3-014:*:*:*:*:*:*:*
    • cpe:2.3:o:cisco:asyncos:14.0.4-005:*:*:*:*:*:*:*
    • cpe:2.3:o:cisco:asyncos:14.5.0-498:*:*:*:*:*:*:*
    • cpe:2.3:o:cisco:asyncos:14.5.1-008:*:*:*:*:*:*:*
    • cpe:2.3:o:cisco:asyncos:14.5.1-016:*:*:*:*:*:*:*
  • (expand)+ 1 more
    • (no CPE)
    • (no CPE)range: 11.7.0-406

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.