PT-2020-4722 · Cisco · Cisco Ftd+1

Published

2020-10-21

·

Updated

2022-05-26

·

CVE-2020-3585

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions: Cisco Adaptive Security Appliance (ASA) Software (affected versions not specified) Cisco Firepower Threat Defense (FTD) Software for Cisco Firepower 1000 Series firewalls (affected versions not specified)
Description: A vulnerability in the TLS handler could allow an unauthenticated, remote attacker to gain access to sensitive information. The issue is due to improper implementation of countermeasures against the Bleichenbacher attack for cipher suites that rely on RSA for key exchange. An attacker could exploit this by sending crafted TLS messages to the device, allowing them to carry out a chosen-ciphertext attack. A successful exploit could enable the attacker to perform cryptanalytic operations that may allow decryption of previously captured TLS sessions to the affected device. To exploit this, an attacker must capture TLS traffic in transit between clients and the affected device and establish a considerable number of TLS connections to the affected device.
Recommendations: At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Side Channel Attack

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2020-05274
CVE-2020-3585

Affected Products

Cisco Asa
Cisco Ftd