---
id: CVE-2020-3299
title: >-
  Multiple Cisco products are affected by a vulnerability in the Snort detection
  engine that could allow an unauthenticated, remote attacker to bypass a
  configured File Policy for HTTP
summary: >-
  Multiple Cisco products are affected by a vulnerability in the Snort detection
  engine that could allow an unauthenticated, remote attacker to bypass a
  configured File Policy for HTTP. The vulnerability is due to incorrect
  detection of mo…
severity: medium
cvss: 5.8
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:L/A:N'
cwe:
  - CWE-693
vendor: cisco
product: secure_firewall_threat_defense
affected:
  - 'secure_firewall_threat_defense >= 6.0.0, < 6.3.0.1'
  - snort < 2.9.13.1
patched:
  - secure_firewall_threat_defense 6.3.0.1
  - snort 2.9.13.1
published: '2020-10-21'
updated: '2026-08-11'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2020-3299'
references:
  - url: 'https://lists.debian.org/debian-lts-announce/2023/02/msg00011.html'
    label: psirt@cisco.com
  - url: >-
      https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ftd-bypass-3eCfd24j
    label: psirt@cisco.com
  - url: 'https://www.debian.org/security/2023/dsa-5354'
    label: psirt@cisco.com
  - url: 'https://lists.debian.org/debian-lts-announce/2023/02/msg00011.html'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ftd-bypass-3eCfd24j
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://www.debian.org/security/2023/dsa-5354'
    label: af854a3a-2127-422b-91ae-364da2661108
tags:
  - nvd
epss: 0.02307
epssPercentile: 0.82599
ingestedAt: '2026-08-11T19:48:28.345Z'
---

## Overview

Multiple Cisco products are affected by a vulnerability in the Snort detection engine that could allow an unauthenticated, remote attacker to bypass a configured File Policy for HTTP. The vulnerability is due to incorrect detection of modified HTTP packets used in chunked responses. An attacker could exploit this vulnerability by sending crafted HTTP packets through an affected device. A successful exploit could allow the attacker to bypass a configured File Policy for HTTP packets and deliver a malicious payload.

## Affected

- `secure_firewall_threat_defense >= 6.0.0, < 6.3.0.1`
- `snort < 2.9.13.1`

## Remediation

Upgrade past the affected range:

- `secure_firewall_threat_defense 6.3.0.1`
- `snort 2.9.13.1`
