Back

HIGH

Cisco Adaptive Security Appliance Software and Firepower Threat Defense Software Media Gateway Control Protocol Denial of Service Vulnerabilities

Published May 6, 2020

Description

Multiple vulnerabilities in the Media Gateway Control Protocol (MGCP) inspection feature of Cisco Adaptive Security Appliance (ASA) Software and Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. The vulnerabilities are due to inefficient memory management. An attacker could exploit these vulnerabilities by sending crafted MGCP packets through an affected device. An exploit could allow the attacker to cause memory exhaustion resulting in a restart of an affected device, causing a DoS condition for traffic traversing the device.

Affected products

Remediation

No remediation recorded yet.

References (2)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner cisco
Published May 6, 2020
Updated Nov 15, 2024
Reserved Dec 12, 2019
CISA Vulnrichment
Updated Nov 15, 2024
NVD
Status Modified
Modified Aug 11, 2026
Red Hat
Severity n/a
Public date n/a
ENISA EUVD
Assigner cisco
Published May 6, 2020
Updated Nov 15, 2024
Exploited since n/a
EUVD-2020-24525