---
id: CVE-2020-3308
title: >-
  A vulnerability in the Image Signature Verification feature of Cisco Firepower
  Threat Defense (FTD) Software could allow an authenticated, remote attacker
  with administrator-level credentials to install a malicious software patch on
  an a…
summary: >-
  A vulnerability in the Image Signature Verification feature of Cisco Firepower
  Threat Defense (FTD) Software could allow an authenticated, remote attacker
  with administrator-level credentials to install a malicious software patch on
  an a…
severity: medium
cvss: 4.9
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:N'
cwe:
  - CWE-347
  - CWE-347
vendor: cisco
product: secure_firewall_threat_defense
affected:
  - secure_firewall_threat_defense < 6.2.2.1
  - secure_firewall_management_center = 6.2.2
  - secure_firewall_management_center = 6.2.3
patched:
  - secure_firewall_threat_defense 6.2.2.1
published: '2020-05-06'
updated: '2026-08-11'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2020-3308'
references:
  - url: >-
      https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sigbypass-FcvPPCeP
    label: psirt@cisco.com
  - url: >-
      https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sigbypass-FcvPPCeP
    label: af854a3a-2127-422b-91ae-364da2661108
tags:
  - nvd
epss: 0.00602
epssPercentile: 0.47205
ingestedAt: '2026-08-11T19:48:28.181Z'
---

## Overview

A vulnerability in the Image Signature Verification feature of Cisco Firepower Threat Defense (FTD) Software could allow an authenticated, remote attacker with administrator-level credentials to install a malicious software patch on an affected device. The vulnerability is due to improper verification of digital signatures for patch images. An attacker could exploit this vulnerability by crafting an unsigned software patch to bypass signature checks and loading it on an affected device. A successful exploit could allow the attacker to boot a malicious software patch image.

## Affected

- `secure_firewall_threat_defense < 6.2.2.1`
- `secure_firewall_management_center = 6.2.2`
- `secure_firewall_management_center = 6.2.3`

## Remediation

Upgrade past the affected range:

- `secure_firewall_threat_defense 6.2.2.1`
