PT-2021-7089 · Cisco · Snort+1
Published
2021-11-02
·
Updated
2022-05-11
·
CVE-2022-20767
CVSS v3.1
8.6
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
Cisco Firepower Threat Defense (FTD) Software versions prior to the fixed version
Description
The issue is related to improper handling of the DNS reputation enforcement rule in the Snort rule evaluation function, which could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. An attacker could exploit this by sending crafted UDP packets through an affected device to force a buildup of UDP connections, resulting in a DoS condition where traffic going through the device is dropped.
Recommendations
For Cisco Firepower Threat Defense (FTD) Software, update to a version that includes the fix for this issue.
As a temporary workaround, consider restricting access to the Snort rule evaluation function until a patch is available.
Avoid using the DNS reputation enforcement rule in the affected Snort rule evaluation function until the issue is resolved.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Allocation of Resources Without Limits
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Cisco Ftd
Snort