Cisco Firepower 9300 Firmware
CVE-2019-12700
A vulnerability in the configuration of the Pluggable Authentication Module (PAM) used in Cisco Firepower Threat Defense (FTD) Software, Cisco Firepower Management Center (FMC) Software, and Cisco FXOS Software could allow an authenticated, remote attacker to cause a denial of service (DoS) condition. The vulnerability is due to improper resource management in the context of user session management. An attacker could exploit this vulnerability by connecting to an affected system and performing many simultaneous successful Secure Shell (SSH) logins. A successful exploit could allow the attacker to exhaust system resources and cause the device to reload, resulting in a DoS condition. To exploit this vulnerability, the attacker needs valid user credentials on the system.
What this means for your business
- It affects Cisco Firepower 9300 Firmware. It matters if your company, or a supplier that handles your data, runs it.
- An attacker can use it remotely, over a network, with an ordinary user login, and without anyone at your company clicking anything.
What to do
- 1Check whether your company or your suppliers run Cisco Firepower 9300 Firmware, and which version. The affected versions are listed further down this page.
- 2If you do, apply the vendor's fix. A patch or vendor advisory has been published.
Not sure if your company is exposed?
Fastnexa’s certified penetration testers can check whether attackers could use this flaw, or others like it, against your websites, apps and network. The full test is free for our first 10 founding clients until 31 December 2026.
Scoring
- CVSS
- 6.5 (v3.1)
- Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H- Weakness
- CWE-400
- Assigned by
- psirt@cisco.com
Dates
- Published
- 2019-10-02
- Last modified
- 2026-08-11
- Sources
- NVD
Affected products
- Cisco Firepower 9300 Firmwarer114, r241
- Cisco Firepower 9300all versions
- Cisco Firepower Extensible Operating System- 2.2, 2.3 - 2.3.1.155, 2.4 - 2.6.1.131
- Cisco Secure Firewall Management Center- 6.1.0, 6.2.0 - 6.2.3.14, 6.2.3 - 6.2.3.7
- Cisco Secure Firewall Threat Defense- 6.1.0, 6.2.0 - 6.2.3.14, 6.2.0 - 6.2.2.5, 6.2.3 - 6.2.3.7
- Cisco Firepower 1000all versions
- Cisco Firepower 2100all versions
As listed in the NVD configuration data. Not a statement about your estate.