← Browse

CVE-2023-20267

Low

No strong exploitation signal.

CVSS base
4.0 MEDIUM
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:N/I:L/A:N
EPSS — probability of exploitation (30 days)
0.4%
36.5th percentile
CISA KEV
Not listed
Weakness / dates
CWE-284
Published 2023-11-01 · modified 2026-08-11

CVSS breakdown

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:N/I:L/A:N

Attack VectorNNetwork
Attack ComplexityHHigh
Privileges RequiredNNone
User InteractionNNone
ScopeCChanged
ConfidentialityNNone
IntegrityLLow
AvailabilityNNone

Timeline

Description

A vulnerability in the IP geolocation rules of Snort 3 could allow an unauthenticated, remote attacker to potentially bypass IP address restrictions. This vulnerability exists because the configuration for IP geolocation rules is not parsed properly. An attacker could exploit this vulnerability by spoofing an IP address until they bypass the restriction. A successful exploit could allow the attacker to bypass location-based IP address restrictions.

Affected

cisco

References

Official: NVD · CVE.org