7.5highHigh

CVE-2020-3255

Cisco Secure Firewall Threat Defense

A vulnerability in the packet processing functionality of Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. The vulnerability is due to inefficient memory management. An attacker could exploit this vulnerability by sending a high rate of IPv4 or IPv6 traffic through an affected device. This traffic would need to match a configured block action in an access control policy. An exploit could allow the attacker to cause a memory exhaustion condition on the affected device, which would result in a DoS for traffic transiting the device, as well as sluggish performance of the management interface. Once the flood is stopped, performance should return to previous states.

Exploitation status

  • A vendor advisory or patch reference has been published.

What the metrics mean

  • It is reachable over a network, without needing local access.
  • For an attacker who can reach it, no special conditions are needed to exploit it.
  • To exploit it, no account is needed.
  • Beyond that, no action by a user is required.

Scoring

CVSS
7.5 (v3.1)
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Weakness
CWE-400
Assigned by
psirt@cisco.com

Dates

Published
2020-05-06
Last modified
2026-08-11
Sources
NVD

Affected products

  • Cisco Secure Firewall Threat Defense6.2.3 - 6.2.3.16, 6.3.0 - 6.3.0.6, 6.4.0 - 6.4.0.9
  • Cisco Asa 5505 Firmware9.10\(1.3\)
  • Cisco Asa 5505all versions
  • Cisco Asa 5510 Firmware9.10\(1.3\)
  • Cisco Asa 5510all versions
  • Cisco Asa 5512-X Firmware9.10\(1.3\)
  • Cisco Asa 5512-Xall versions
  • Cisco Asa 5515-X Firmware9.10\(1.3\)
  • Cisco Asa 5515-Xall versions
  • Cisco Asa 5520 Firmware9.10\(1.3\)
  • Cisco Asa 5520all versions
  • Cisco Asa 5525-X Firmware9.10\(1.3\)

As listed in the NVD configuration data. Not a statement about your estate.

References