PT-2022-5699 · Cisco · Cisco Firepower Management Center+1
Published
2022-11-09
·
Updated
2024-11-26
·
CVE-2022-20854
CVSS v2.0
7.8
High
| Vector | AV:N/AC:L/Au:N/C:N/I:N/A:C |
Name of the Vulnerable Software and Affected Versions
Cisco Firepower Threat Defense (FTD) and Cisco Firepower Management Center (FMC) (affected versions not specified)
Description
The issue is related to an uncontrolled resource consumption vulnerability in the implementation of the SSH protocol in Cisco Firepower Threat Defense (FTD) and Cisco Firepower Management Center (FMC) software. This vulnerability could allow a remote attacker to cause a denial of service (DoS) condition on an affected device. The vulnerability is due to improper error handling when an SSH session fails to be established. An attacker could exploit this vulnerability by sending a high rate of crafted SSH connections to the instance, potentially causing resource exhaustion and resulting in a reboot on the affected device.
Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Improper Handling of Exceptional Conditions
Resource Exhaustion
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Cisco Firepower Management Center
Cisco Ftd