PT-2024-9437 · Cisco · Cisco Ftd+1

Published

2024-10-23

·

Updated

2025-08-06

·

CVE-2024-20330

CVSS v3.1

8.6

High

VectorAV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions: Cisco Firepower Threat Defense (FTD) Software for Cisco Firepower 2100 Series Appliances (affected versions not specified) Cisco Adaptive Security Appliance (ASA) (affected versions not specified)
Description: The issue is related to improper memory management in the Snort TCP and UDP detection engine, which can cause memory corruption when processing specific packets. An attacker could exploit this by sending crafted packets, potentially leading to a denial of service (DoS) condition where the Snort detection engine restarts repeatedly. This condition affects only the traffic examined by the Snort detection engine, and the device remains manageable over the network. The memory corruption cannot be cleared until the device is manually reloaded, causing the Snort detection engine to crash repeatedly and drop traffic.
Recommendations: For Cisco Firepower Threat Defense (FTD) Software: At the moment, there is no information about a newer version that contains a fix for this vulnerability. For Cisco Adaptive Security Appliance (ASA): At the moment, there is no information about a newer version that contains a fix for this vulnerability.

DoS

Access of Memory Location After End of Buffer

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2024-11132
CVE-2024-20330

Affected Products

Cisco Asa
Cisco Ftd