5.9mediumMedium
CVE-2017-3887
Cisco Secure Firewall Threat Defense
A vulnerability in the detection engine that handles Secure Sockets Layer (SSL) packets for Cisco Firepower System Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition because the Snort process unexpectedly restarts. This vulnerability affects Cisco Firepower System Software prior to the first fixed release when it is configured with an SSL Decrypt-Resign policy. More Information: CSCvb62292. Known Affected Releases: 6.0.1 6.1.0 6.2.0. Known Fixed Releases: 6.2.0 6.1.0.2.
Exploitation status
- A vendor advisory or patch reference has been published.
What the metrics mean
- It is reachable over a network, without needing local access.
- For an attacker who can reach it, exploitation depends on conditions outside the attacker's control.
- To exploit it, no account is needed.
- Beyond that, no action by a user is required.
Scoring
- CVSS
- 5.9 (v3.0)
- Vector
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H- Weakness
- CWE-755
- Assigned by
- psirt@cisco.com
Dates
- Published
- 2017-04-07
- Last modified
- 2026-08-11
- Sources
- NVD
Affected products
- Cisco Secure Firewall Threat Defense6.0.1, 6.1.0, 6.2.0
As listed in the NVD configuration data. Not a statement about your estate.