Back

HIGH

Cisco Firepower 1000 Series SSL/TLS Denial of Service Vulnerability

Published May 6, 2020

Description

A vulnerability in the Secure Sockets Layer (SSL)/Transport Layer Security (TLS) handler of Cisco Firepower Threat Defense (FTD) Software when running on the Cisco Firepower 1000 Series platform could allow an unauthenticated, remote attacker to trigger a denial of service (DoS) condition on an affected device. The vulnerability is due to a communication error between internal functions. An attacker could exploit this vulnerability by sending a crafted SSL/TLS message to an affected device. A successful exploit could allow the attacker to cause a buffer underrun, which leads to a crash. The crash causes the affected device to reload.

Affected products

Remediation

No remediation recorded yet.

Metrics

References (1)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner cisco
Published May 6, 2020
Updated Nov 15, 2024
Reserved Dec 12, 2019
CISA Vulnrichment
Updated Nov 15, 2024
NVD
Status Modified
Modified Aug 11, 2026
Red Hat
Severity n/a
Public date n/a