PT-2020-2505 · Cisco · Cisco Ftd+1

Published

2020-05-06

·

Updated

2021-08-12

·

CVE-2020-3188

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
Name of the Vulnerable Software and Affected Versions Cisco Firepower Threat Defense (FTD) Software (affected versions not specified)
Description The issue is related to errors in resource management, which could allow a remote attacker to cause a denial of service (DoS) condition by creating a large number of remote management connections on the vulnerable device. The vulnerability exists due to a long default session timeout period for specific remote management connections. An attacker could exploit this by sending a large and sustained number of crafted remote management connections, resulting in a buildup of connections over time. This could cause the remote management interface or Cisco Firepower Device Manager (FDM) to stop responding, with other management functions going offline, resulting in a DoS condition. The DoS condition would be isolated to remote management only, and user traffic flowing through the device would not be affected.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Insufficient Session Expiration

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2020-02516
CVE-2020-3188

Affected Products

Cisco Firepower Device Manager
Cisco Ftd