CVE-2024-20407
Cisco Firepower Threat Defense (FTD) vulnerability analysis and mitigation

Overview

A vulnerability (CVE-2024-20407) has been identified in the interaction between the TCP Intercept feature and the Snort 3 detection engine on Cisco Firepower Threat Defense (FTD) Software. This vulnerability, discovered during the resolution of a Cisco TAC support case and disclosed on October 23, 2024, could allow an unauthenticated, remote attacker to bypass configured policies on affected systems. Notably, devices configured with Snort 2 are not affected by this vulnerability (Cisco Advisory).

Technical details

The vulnerability stems from a logic error in handling embryonic (half-open) TCP connections. It has been assigned a CVSS base score of 5.8 (Medium) with the vector string CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:L/A:N. The vulnerability is specifically associated with CWE-399 (Resource Management Errors). The default value for embryonic connections is 0 (unlimited connections), and deployments with this default configuration are considered not vulnerable (Cisco Advisory).

Impact

A successful exploitation of this vulnerability could allow unintended traffic to enter the network protected by the affected device. This bypass of configured policies could potentially compromise the security posture of the protected network (Cisco Advisory).

Mitigation and workarounds

Cisco has released software updates that address this vulnerability. Additionally, a workaround is available by turning off pkt-decode-optimization using the 'no asp inspect-dp pkt-decode-optimization' FTD CLI command. However, customers should evaluate the applicability and effectiveness of this workaround in their environment as it may impact network functionality or performance (Cisco Advisory).

Additional resources


SourceThis report was generated using AI

Related Cisco Firepower Threat Defense (FTD) vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2025-20333CRITICAL9.9
  • Cisco Adaptive Security Appliance (ASA)Cisco Adaptive Security Appliance (ASA)
  • cpe:2.3:a:cisco:firepower_threat_defense
YesYesSep 25, 2025
CVE-2025-20363CRITICAL9
  • Cisco Adaptive Security Appliance (ASA)Cisco Adaptive Security Appliance (ASA)
  • cpe:2.3:a:cisco:firepower_threat_defense
NoYesSep 25, 2025
CVE-2025-20362HIGH8.6
  • Cisco Adaptive Security Appliance (ASA)Cisco Adaptive Security Appliance (ASA)
  • cpe:2.3:a:cisco:firepower_threat_defense
YesYesSep 25, 2025
CVE-2025-20263HIGH8.6
  • Cisco Adaptive Security Appliance (ASA)Cisco Adaptive Security Appliance (ASA)
  • cpe:2.3:a:cisco:firepower_threat_defense
NoYesAug 14, 2025
CVE-2025-20268MEDIUM5.8
  • Cisco Firepower Threat Defense (FTD)Cisco Firepower Threat Defense (FTD)
  • cpe:2.3:a:cisco:firepower_threat_defense
NoYesAug 14, 2025

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management