8.6
CVE-2020-3283
- EPSS 1.96%
- Veröffentlicht 06.05.2020 17:15:12
- Zuletzt bearbeitet 11.08.2026 19:33:44
- Erkennungen
Cisco Firepower 1000 Series SSL/TLS Denial of Service Vulnerability
A vulnerability in the Secure Sockets Layer (SSL)/Transport Layer Security (TLS) handler of Cisco Firepower Threat Defense (FTD) Software when running on the Cisco Firepower 1000 Series platform could allow an unauthenticated, remote attacker to trigger a denial of service (DoS) condition on an affected device. The vulnerability is due to a communication error between internal functions. An attacker could exploit this vulnerability by sending a crafted SSL/TLS message to an affected device. A successful exploit could allow the attacker to cause a buffer underrun, which leads to a crash. The crash causes the affected device to reload.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Cisco ≫ Secure Firewall Threat Defense Version >= 6.4.0 < 6.4.0.9
Cisco ≫ Firepower 1010 Version -
Cisco ≫ Firepower 1020 Version -
Cisco ≫ Firepower 1030 Version -
Cisco ≫ Firepower 1040 Version -
Cisco ≫ Firepower 1020 Version -
Cisco ≫ Firepower 1030 Version -
Cisco ≫ Firepower 1040 Version -
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 1.96% | 0.777 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 8.6 | 3.9 | 4 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H
|
| NIST | 5 | 10 | 2.9 |
AV:N/AC:L/Au:N/C:N/I:N/A:P
|
| Cisco PSIRT | 8.6 | 3.9 | 4 |
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H
|
CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer
The product performs operations on a memory buffer, but it reads from or writes to a memory location outside the buffer's intended boundary. This may result in read or write operations on unexpected memory locations that could be linked to other variables, data structures, or internal program data.
CWE-787 Out-of-bounds Write
The product writes data past the end, or before the beginning, of the intended buffer.
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ftd-tls-dos-4v5nmWtZ