PT-2019-14861 · Cisco · Snort+1

Published

2019-02-21

·

Updated

2020-10-16

·

CVE-2019-1691

CVSS v3.1

5.8

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:L
Name of the Vulnerable Software and Affected Versions Cisco Firepower Threat Defense Software versions prior to 6.2.3.4
Description A vulnerability in the detection engine could allow an unauthenticated, remote attacker to cause the unexpected restart of the SNORT detection engine, resulting in a denial of service (DoS) condition. The issue is due to incomplete error handling of the SSL or TLS packet header during connection establishment. An attacker could exploit this by sending a crafted SSL or TLS packet during the connection handshake, allowing them to cause the SNORT detection engine to restart, resulting in a partial DoS condition.
Recommendations For versions prior to 6.2.3.4, update to version 6.2.3.4 or later to resolve the issue. As a temporary workaround, consider implementing additional network traffic monitoring to quickly detect and respond to potential exploitation attempts. Restrict access to the detection engine to minimize the risk of exploitation.

Fix

Improper Handling of Exceptional Conditions

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2019-1691

Affected Products

Cisco Ftd
Snort