PT-2020-4461 · Cisco · Cisco Asa+1
Published
2020-10-21
·
Updated
2023-08-16
·
CVE-2020-3554
CVSS v3.1
8.6
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
Cisco Adaptive Security Appliance versions prior to the fixed release
Cisco Firepower Threat Defense versions prior to the fixed release
Description
The issue is related to a memory exhaustion condition in the TCP packet processing of the software, which could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. An attacker could exploit this by sending a high rate of crafted TCP traffic through an affected device, exhausting device resources and resulting in a DoS condition for traffic transiting the device.
Recommendations
For Cisco Adaptive Security Appliance, update to a fixed release to resolve the issue.
For Cisco Firepower Threat Defense, update to a fixed release to resolve the issue.
As a temporary workaround, consider restricting the rate of TCP traffic through the affected device to minimize the risk of exploitation.
Fix
DoS
Resource Exhaustion
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Cisco Asa
Cisco Ftd