---
id: CVE-2020-3285
title: >-
  A vulnerability in the Transport Layer Security version 1.3 (TLS 1.3) policy
  with URL category functionality for Cisco Firepower Threat Defense (FTD)
  Software could allow an unauthenticated, remote attacker to bypass a
  configured TLS 1.3…
summary: >-
  A vulnerability in the Transport Layer Security version 1.3 (TLS 1.3) policy
  with URL category functionality for Cisco Firepower Threat Defense (FTD)
  Software could allow an unauthenticated, remote attacker to bypass a
  configured TLS 1.3…
severity: medium
cvss: 5.8
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:L/A:N'
cwe:
  - CWE-693
vendor: cisco
product: secure_firewall_threat_defense
affected:
  - 'secure_firewall_threat_defense >= 6.4.0, <= 6.4.0.8'
published: '2020-05-06'
updated: '2026-08-11'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2020-3285'
references:
  - url: >-
      https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ssl-bypass-O5tGum2n
    label: psirt@cisco.com
  - url: >-
      https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ssl-bypass-O5tGum2n
    label: af854a3a-2127-422b-91ae-364da2661108
tags:
  - nvd
epss: 0.01455
epssPercentile: 0.72314
ingestedAt: '2026-08-11T19:48:27.815Z'
---

## Overview

A vulnerability in the Transport Layer Security version 1.3 (TLS 1.3) policy with URL category functionality for Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to bypass a configured TLS 1.3 policy to block traffic for a specific URL. The vulnerability is due to a logic error with Snort handling of the connection with the TLS 1.3 policy and URL category configuration. An attacker could exploit this vulnerability by sending crafted TLS 1.3 connections to an affected device. A successful exploit could allow the attacker to bypass the TLS 1.3 policy and access URLs that are outside the affected device and normally would be dropped.

## Affected

- `secure_firewall_threat_defense >= 6.4.0, <= 6.4.0.8`

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
