PT-2018-2133 · Cisco · Cisco Ftd

Published

2018-10-03

·

Updated

2020-08-31

·

CVE-2018-15390

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions Cisco Firepower Threat Defense (FTD) Software (affected versions not specified)
Description A vulnerability in the FTP inspection engine could allow an unauthenticated, remote attacker to cause an affected device to reload, resulting in a denial of service (DoS) condition. This occurs because the software fails to release spinlocks when a device is running low on system memory, specifically when configured to apply FTP inspection and an access control rule to transit traffic, and the access control rule is associated with an FTP file policy. An attacker could exploit this by sending a high rate of transit traffic through an affected device to cause a low-memory condition, potentially leading to a software panic and a temporary DoS condition.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Improper Locking

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2019-00085
CVE-2018-15390

Affected Products

Cisco Ftd