PT-2020-4462 · Cisco · Cisco Asa+1
Santosh Krishnamurthy
·
Published
2020-10-21
·
Updated
2023-08-16
·
CVE-2020-3373
CVSS v3.1
8.6
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
Cisco Adaptive Security Appliance versions prior to the fixed version
Cisco Firepower Threat Defense versions prior to the fixed version
Description
The issue is related to an uncontrolled resource consumption in the software of Cisco Adaptive Security Appliance and Cisco Firepower Threat Defense. It could allow a remote attacker to cause a denial of service condition by sending specially crafted fragmented IP traffic to the targeted device. This is due to improper error handling during IP fragment reassembly, which could lead to a memory leak, preventing traffic from being processed and resulting in a denial of service condition. The device may require a manual reboot to recover. The vulnerability affects both IP Version 4 and IP Version 6 traffic.
Recommendations
For Cisco Adaptive Security Appliance versions prior to the fixed version, update to the fixed release to resolve the issue.
For Cisco Firepower Threat Defense versions prior to the fixed version, update to the fixed release to resolve the issue.
As a temporary workaround, consider restricting access to the device to minimize the risk of exploitation until a patch is available.
Fix
DoS
Memory Leak
Resource Exhaustion
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Cisco Asa
Cisco Ftd