CVE-2020-3577
Cisco Firepower Threat Defense Software Inline Pair/Passive Mode Denial of Service Vulnerability
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
A vulnerability in the ingress packet processing path of Cisco Firepower Threat Defense (FTD) Software for interfaces that are configured either as Inline Pair or in Passive mode could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) condition. The vulnerability is due to insufficient validation when Ethernet frames are processed. An attacker could exploit this vulnerability by sending malicious Ethernet frames through an affected device. A successful exploit could allow the attacker do either of the following: Fill the /ngfw partition on the device: A full /ngfw partition could result in administrators being unable to log in to the device (including logging in through the console port) or the device being unable to boot up correctly. Note: Manual intervention is required to recover from this situation. Customers are advised to contact the Cisco Technical Assistance Center (TAC) to help recover a device in this condition. Cause a process crash: The process crash would cause the device to reload. No manual intervention is necessary to recover the device after the reload.
Una vulnerabilidad en la ruta de procesamiento de paquetes de entrada de Cisco Firepower Threat Defense (FTD) Software para interfaces que están configuradas como Inline Pair o en modo Passive podría permitir a un atacante adyacente no autenticado causar una condición de denegación de servicio (DoS). La vulnerabilidad es debido a una comprobación insuficiente cuando son procesadas las tramas Ethernet. Un atacante podría explotar esta vulnerabilidad mediante el envío de tramas Ethernet maliciosas por medio de un dispositivo afectado. Una explotación con éxito podría permitir a un atacante causar una de las siguientes acciones: Llenar la partición /ngfw en el dispositivo: una partición /ngfw completa podría resultar en que los administradores no puedan iniciar sesión en el dispositivo (incluido el inicio de sesión por medio del puerto de la consola) o el dispositivo no puede arrancar correctamente. Nota: Se requiere una intervención manual para recuperarse de esta situación. Se recomienda a los clientes que se comuniquen con el Cisco Technical Assistance Center (TAC) para ayudar a recuperar un dispositivo en esta condición. Causar un bloqueo del proceso: el bloqueo del proceso haría que el dispositivo se recargara. No es necesaria ninguna intervención manual para recuperar el dispositivo después de la recarga
CVSS Scores
SSVC
- Decision:-
Timeline
- 2019-12-12 CVE Reserved
- 2020-10-21 CVE Published
- 2023-07-07 EPSS Updated
- 2024-09-16 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-20: Improper Input Validation
CAPEC
References (1)
URL | Tag | Source |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Cisco Search vendor "Cisco" | Firepower Threat Defense Search vendor "Cisco" for product "Firepower Threat Defense" | < 6.3.0.6 Search vendor "Cisco" for product "Firepower Threat Defense" and version " < 6.3.0.6" | - |
Affected
| ||||||
Cisco Search vendor "Cisco" | Firepower Threat Defense Search vendor "Cisco" for product "Firepower Threat Defense" | >= 6.4.0 < 6.4.0.10 Search vendor "Cisco" for product "Firepower Threat Defense" and version " >= 6.4.0 < 6.4.0.10" | - |
Affected
| ||||||
Cisco Search vendor "Cisco" | Firepower Threat Defense Search vendor "Cisco" for product "Firepower Threat Defense" | >= 6.5.0 < 6.5.0.5 Search vendor "Cisco" for product "Firepower Threat Defense" and version " >= 6.5.0 < 6.5.0.5" | - |
Affected
| ||||||
Cisco Search vendor "Cisco" | Firepower Threat Defense Search vendor "Cisco" for product "Firepower Threat Defense" | >= 6.6.0 < 6.6.1 Search vendor "Cisco" for product "Firepower Threat Defense" and version " >= 6.6.0 < 6.6.1" | - |
Affected
|