CVE-2020-3255
Cisco Secure Firewall Threat Defense
A vulnerability in the packet processing functionality of Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. The vulnerability is due to inefficient memory management. An attacker could exploit this vulnerability by sending a high rate of IPv4 or IPv6 traffic through an affected device. This traffic would need to match a configured block action in an access control policy. An exploit could allow the attacker to cause a memory exhaustion condition on the affected device, which would result in a DoS for traffic transiting the device, as well as sluggish performance of the management interface. Once the flood is stopped, performance should return to previous states.
Exploitation status
- A vendor advisory or patch reference has been published.
What the metrics mean
- It is reachable over a network, without needing local access.
- For an attacker who can reach it, no special conditions are needed to exploit it.
- To exploit it, no account is needed.
- Beyond that, no action by a user is required.
Scoring
- CVSS
- 7.5 (v3.1)
- Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H- Weakness
- CWE-400
- Assigned by
- psirt@cisco.com
Dates
- Published
- 2020-05-06
- Last modified
- 2026-08-11
- Sources
- NVD
Affected products
- Cisco Secure Firewall Threat Defense6.2.3 - 6.2.3.16, 6.3.0 - 6.3.0.6, 6.4.0 - 6.4.0.9
- Cisco Asa 5505 Firmware9.10\(1.3\)
- Cisco Asa 5505all versions
- Cisco Asa 5510 Firmware9.10\(1.3\)
- Cisco Asa 5510all versions
- Cisco Asa 5512-X Firmware9.10\(1.3\)
- Cisco Asa 5512-Xall versions
- Cisco Asa 5515-X Firmware9.10\(1.3\)
- Cisco Asa 5515-Xall versions
- Cisco Asa 5520 Firmware9.10\(1.3\)
- Cisco Asa 5520all versions
- Cisco Asa 5525-X Firmware9.10\(1.3\)
As listed in the NVD configuration data. Not a statement about your estate.