PT-2021-7089 · Cisco · Snort+1

Published

2021-11-02

·

Updated

2022-05-11

·

CVE-2022-20767

CVSS v3.1

8.6

High

VectorAV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Cisco Firepower Threat Defense (FTD) Software versions prior to the fixed version
Description The issue is related to improper handling of the DNS reputation enforcement rule in the Snort rule evaluation function, which could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. An attacker could exploit this by sending crafted UDP packets through an affected device to force a buildup of UDP connections, resulting in a DoS condition where traffic going through the device is dropped.
Recommendations For Cisco Firepower Threat Defense (FTD) Software, update to a version that includes the fix for this issue. As a temporary workaround, consider restricting access to the Snort rule evaluation function until a patch is available. Avoid using the DNS reputation enforcement rule in the affected Snort rule evaluation function until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Allocation of Resources Without Limits

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2022-03262
CVE-2022-20767

Affected Products

Cisco Ftd
Snort