Back

HIGH

Cisco Firepower Threat Defense Software VPN System Logging Denial of Service Vulnerability

Published May 6, 2020

Description

A vulnerability in the VPN System Logging functionality for Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause a memory leak that can deplete system memory over time, which can cause unexpected system behaviors or device crashes. The vulnerability is due to the system memory not being properly freed for a VPN System Logging event generated when a VPN session is created or deleted. An attacker could exploit this vulnerability by repeatedly creating or deleting a VPN tunnel connection, which could leak a small amount of system memory for each logging event. A successful exploit could allow the attacker to cause system memory depletion, which can lead to a systemwide denial of service (DoS) condition. The attacker does not have any control of whether VPN System Logging is configured or not on the device, but it is enabled by default.

Affected products

Remediation

No remediation recorded yet.

References (2)

Change history (0)

No recorded changes yet.

Sources

CVE.org / MITRE

Status PUBLISHED
Assigner cisco
Published May 6, 2020
Updated Nov 15, 2024
Reserved Dec 12, 2019

CISA Vulnrichment

Updated Nov 15, 2024

NVD

Status Modified
Modified Aug 11, 2026

Red Hat

No data

ENISA EUVD

Assigner cisco
Published May 6, 2020
Updated Nov 15, 2024

GitHub

No data