theinfosecnews

CVE-2023-20269

CISA KEV

Published September 13, 2023 · Updated April 3, 2026

high
Official Description+

Cisco Adaptive Security Appliance and Firepower Threat Defense contain an unauthorized access vulnerability that could allow an unauthenticated, remote attacker to conduct a brute force attack in an attempt to identify valid username and password combinations or establish a clientless SSL VPN session with an unauthorized user.

Affected Products

VendorProduct
CiscoAdaptive Security Appliance and Firepower Threat Defense

Patch Status

Patch by 2023-10-04

Recommended Actions

  1. Check if your systems use any of the affected products listed above.
  2. Apply vendor patches immediately if available.
  3. This vulnerability is in CISA's Known Exploited Vulnerabilities catalog — prioritize remediation.
  4. Monitor vendor advisories for updates and additional mitigations.
  5. Review logs for indicators of compromise related to CVE-2023-20269.