CVE-2019-12700
Cisco FTD, FMC, and FXOS Software Pluggable Authentication Module Denial of Service Vulnerability
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
A vulnerability in the configuration of the Pluggable Authentication Module (PAM) used in Cisco Firepower Threat Defense (FTD) Software, Cisco Firepower Management Center (FMC) Software, and Cisco FXOS Software could allow an authenticated, remote attacker to cause a denial of service (DoS) condition. The vulnerability is due to improper resource management in the context of user session management. An attacker could exploit this vulnerability by connecting to an affected system and performing many simultaneous successful Secure Shell (SSH) logins. A successful exploit could allow the attacker to exhaust system resources and cause the device to reload, resulting in a DoS condition. To exploit this vulnerability, the attacker needs valid user credentials on the system.
Una vulnerabilidad en la configuración del Pluggable Authentication Module (PAM) utilizado en el Software Cisco Firepower Threat Defense (FTD), el Software Cisco Firepower Management Center (FMC) y el Software Cisco FXOS, podría permitir a un atacante remoto autenticado causar una condición de denegación de servicio (DoS). La vulnerabilidad es debido a la administración de recursos inapropiada en el contexto de la administración de sesión del usuario. Un atacante podría explotar esta vulnerabilidad mediante la conexión a un sistema afectado y realizando muchos inicios de sesión con éxito de Secure Shell (SSH) simultáneos. Una explotación con éxito podría permitir al atacante agotar los recursos del sistema y causar que el dispositivo se recargue, resultando en una condición DoS. Para explotar esta vulnerabilidad, el atacante necesita credenciales de usuario válidas en el sistema.
CVSS Scores
SSVC
- Decision:Track
Timeline
- 2019-06-04 CVE Reserved
- 2019-10-02 CVE Published
- 2023-05-08 EPSS Updated
- 2024-11-21 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-400: Uncontrolled Resource Consumption
CAPEC
References (1)
URL | Tag | Source |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Cisco Search vendor "Cisco" | Firepower 9300 Firmware Search vendor "Cisco" for product "Firepower 9300 Firmware" | r114 Search vendor "Cisco" for product "Firepower 9300 Firmware" and version "r114" | - |
Affected
| in | Cisco Search vendor "Cisco" | Firepower 9300 Search vendor "Cisco" for product "Firepower 9300" | - | - |
Safe
|
Cisco Search vendor "Cisco" | Firepower 9300 Firmware Search vendor "Cisco" for product "Firepower 9300 Firmware" | r241 Search vendor "Cisco" for product "Firepower 9300 Firmware" and version "r241" | - |
Affected
| in | Cisco Search vendor "Cisco" | Firepower 9300 Search vendor "Cisco" for product "Firepower 9300" | - | - |
Safe
|
Cisco Search vendor "Cisco" | Firepower Management Center Search vendor "Cisco" for product "Firepower Management Center" | <= 6.1.0 Search vendor "Cisco" for product "Firepower Management Center" and version " <= 6.1.0" | - |
Affected
| in | Cisco Search vendor "Cisco" | Firepower 1000 Search vendor "Cisco" for product "Firepower 1000" | - | - |
Safe
|
Cisco Search vendor "Cisco" | Firepower Management Center Search vendor "Cisco" for product "Firepower Management Center" | <= 6.1.0 Search vendor "Cisco" for product "Firepower Management Center" and version " <= 6.1.0" | - |
Affected
| in | Cisco Search vendor "Cisco" | Firepower 2100 Search vendor "Cisco" for product "Firepower 2100" | - | - |
Safe
|
Cisco Search vendor "Cisco" | Firepower Management Center Search vendor "Cisco" for product "Firepower Management Center" | >= 6.2.0 < 6.2.3.14 Search vendor "Cisco" for product "Firepower Management Center" and version " >= 6.2.0 < 6.2.3.14" | - |
Affected
| in | Cisco Search vendor "Cisco" | Firepower 1000 Search vendor "Cisco" for product "Firepower 1000" | - | - |
Safe
|
Cisco Search vendor "Cisco" | Firepower Management Center Search vendor "Cisco" for product "Firepower Management Center" | >= 6.2.0 < 6.2.3.14 Search vendor "Cisco" for product "Firepower Management Center" and version " >= 6.2.0 < 6.2.3.14" | - |
Affected
| in | Cisco Search vendor "Cisco" | Firepower 2100 Search vendor "Cisco" for product "Firepower 2100" | - | - |
Safe
|
Cisco Search vendor "Cisco" | Firepower Threat Defense Search vendor "Cisco" for product "Firepower Threat Defense" | <= 6.1.0 Search vendor "Cisco" for product "Firepower Threat Defense" and version " <= 6.1.0" | - |
Affected
| in | Cisco Search vendor "Cisco" | Firepower 1000 Search vendor "Cisco" for product "Firepower 1000" | - | - |
Safe
|
Cisco Search vendor "Cisco" | Firepower Threat Defense Search vendor "Cisco" for product "Firepower Threat Defense" | <= 6.1.0 Search vendor "Cisco" for product "Firepower Threat Defense" and version " <= 6.1.0" | - |
Affected
| in | Cisco Search vendor "Cisco" | Firepower 2100 Search vendor "Cisco" for product "Firepower 2100" | - | - |
Safe
|
Cisco Search vendor "Cisco" | Firepower Threat Defense Search vendor "Cisco" for product "Firepower Threat Defense" | >= 6.2.0 < 6.2.3.14 Search vendor "Cisco" for product "Firepower Threat Defense" and version " >= 6.2.0 < 6.2.3.14" | - |
Affected
| in | Cisco Search vendor "Cisco" | Firepower 1000 Search vendor "Cisco" for product "Firepower 1000" | - | - |
Safe
|
Cisco Search vendor "Cisco" | Firepower Threat Defense Search vendor "Cisco" for product "Firepower Threat Defense" | >= 6.2.0 < 6.2.3.14 Search vendor "Cisco" for product "Firepower Threat Defense" and version " >= 6.2.0 < 6.2.3.14" | - |
Affected
| in | Cisco Search vendor "Cisco" | Firepower 2100 Search vendor "Cisco" for product "Firepower 2100" | - | - |
Safe
|
Cisco Search vendor "Cisco" | Firepower Extensible Operating System Search vendor "Cisco" for product "Firepower Extensible Operating System" | <= 2.2 Search vendor "Cisco" for product "Firepower Extensible Operating System" and version " <= 2.2" | - |
Affected
| ||||||
Cisco Search vendor "Cisco" | Firepower Extensible Operating System Search vendor "Cisco" for product "Firepower Extensible Operating System" | >= 2.3 < 2.3.1.155 Search vendor "Cisco" for product "Firepower Extensible Operating System" and version " >= 2.3 < 2.3.1.155" | - |
Affected
| ||||||
Cisco Search vendor "Cisco" | Firepower Extensible Operating System Search vendor "Cisco" for product "Firepower Extensible Operating System" | >= 2.4 < 2.6.1.131 Search vendor "Cisco" for product "Firepower Extensible Operating System" and version " >= 2.4 < 2.6.1.131" | - |
Affected
| ||||||
Cisco Search vendor "Cisco" | Firepower Management Center Search vendor "Cisco" for product "Firepower Management Center" | <= 6.1.0 Search vendor "Cisco" for product "Firepower Management Center" and version " <= 6.1.0" | - |
Affected
| ||||||
Cisco Search vendor "Cisco" | Firepower Management Center Search vendor "Cisco" for product "Firepower Management Center" | >= 6.2.0 < 6.2.3.14 Search vendor "Cisco" for product "Firepower Management Center" and version " >= 6.2.0 < 6.2.3.14" | - |
Affected
| ||||||
Cisco Search vendor "Cisco" | Firepower Management Center Search vendor "Cisco" for product "Firepower Management Center" | >= 6.2.3 < 6.2.3.7 Search vendor "Cisco" for product "Firepower Management Center" and version " >= 6.2.3 < 6.2.3.7" | - |
Affected
| ||||||
Cisco Search vendor "Cisco" | Firepower Threat Defense Search vendor "Cisco" for product "Firepower Threat Defense" | <= 6.1.0 Search vendor "Cisco" for product "Firepower Threat Defense" and version " <= 6.1.0" | - |
Affected
| ||||||
Cisco Search vendor "Cisco" | Firepower Threat Defense Search vendor "Cisco" for product "Firepower Threat Defense" | >= 6.2.0 < 6.2.2.5 Search vendor "Cisco" for product "Firepower Threat Defense" and version " >= 6.2.0 < 6.2.2.5" | - |
Affected
| ||||||
Cisco Search vendor "Cisco" | Firepower Threat Defense Search vendor "Cisco" for product "Firepower Threat Defense" | >= 6.2.3 < 6.2.3.7 Search vendor "Cisco" for product "Firepower Threat Defense" and version " >= 6.2.3 < 6.2.3.7" | - |
Affected
|