CVE-2020-3585
Cisco Firepower 1000 Series Bleichenbacher Attack Vulnerability
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
A vulnerability in the TLS handler of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software for Cisco Firepower 1000 Series firewalls could allow an unauthenticated, remote attacker to gain access to sensitive information. The vulnerability is due to improper implementation of countermeasures against the Bleichenbacher attack for cipher suites that rely on RSA for key exchange. An attacker could exploit this vulnerability by sending crafted TLS messages to the device, which would act as an oracle and allow the attacker to carry out a chosen-ciphertext attack. A successful exploit could allow the attacker to perform cryptanalytic operations that may allow decryption of previously captured TLS sessions to the affected device. To exploit this vulnerability, an attacker must be able to perform both of the following actions: Capture TLS traffic that is in transit between clients and the affected device Actively establish a considerable number of TLS connections to the affected device
Una vulnerabilidad en el manejador TLS de Cisco Adaptive Security Appliance (ASA) Software y Cisco Firepower Threat Defense (FTD) Software para los firewalls Cisco Firepower 1000 Series, podría permitir a un atacante remoto no autenticado obtener acceso a información confidencial. La vulnerabilidad es debido a una implementación inapropiada de contramedidas contra el ataque Bleichenbacher para conjuntos de cifrado que dependen de RSA para el intercambio de claves. Un atacante podría explotar esta vulnerabilidad mediante el envío de mensajes TLS diseñados hacia el dispositivo, que actuaría como un oráculo y permitiría a un atacante conducir un ataque de texto cifrado elegido. Una explotación con éxito podría permitir a un atacante realizar operaciones criptoanalíticas que podrían habilitar el descifrado de sesiones TLS capturadas previamente en el dispositivo afectado. Para aprovechar esta vulnerabilidad, un atacante necesita ser capaz de realizar ambas de las siguientes acciones: Capturar el tráfico TLS que esta en transito entre clientes y el dispositivo afectado que establece Activamente un número considerable de conexiones TLS hacia el dispositivo afectado
CVSS Scores
SSVC
- Decision:Attend
Timeline
- 2019-12-12 CVE Reserved
- 2020-10-21 CVE Published
- 2023-10-25 EPSS Updated
- 2024-11-13 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-203: Observable Discrepancy
CAPEC
References (1)
URL | Tag | Source |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-asaftd-tls-bb-2g9uWkP | 2023-11-07 |
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Cisco Search vendor "Cisco" | Firepower Threat Defense Search vendor "Cisco" for product "Firepower Threat Defense" | < 6.4.0.10 Search vendor "Cisco" for product "Firepower Threat Defense" and version " < 6.4.0.10" | - |
Affected
| in | Cisco Search vendor "Cisco" | Firepower 1000 Search vendor "Cisco" for product "Firepower 1000" | - | - |
Safe
|
Cisco Search vendor "Cisco" | Firepower Threat Defense Search vendor "Cisco" for product "Firepower Threat Defense" | < 6.4.0.10 Search vendor "Cisco" for product "Firepower Threat Defense" and version " < 6.4.0.10" | - |
Affected
| in | Cisco Search vendor "Cisco" | Firepower 1010 Search vendor "Cisco" for product "Firepower 1010" | - | - |
Safe
|
Cisco Search vendor "Cisco" | Firepower Threat Defense Search vendor "Cisco" for product "Firepower Threat Defense" | < 6.4.0.10 Search vendor "Cisco" for product "Firepower Threat Defense" and version " < 6.4.0.10" | - |
Affected
| in | Cisco Search vendor "Cisco" | Firepower 1120 Search vendor "Cisco" for product "Firepower 1120" | - | - |
Safe
|
Cisco Search vendor "Cisco" | Firepower Threat Defense Search vendor "Cisco" for product "Firepower Threat Defense" | < 6.4.0.10 Search vendor "Cisco" for product "Firepower Threat Defense" and version " < 6.4.0.10" | - |
Affected
| in | Cisco Search vendor "Cisco" | Firepower 1140 Search vendor "Cisco" for product "Firepower 1140" | - | - |
Safe
|
Cisco Search vendor "Cisco" | Firepower Threat Defense Search vendor "Cisco" for product "Firepower Threat Defense" | < 6.4.0.10 Search vendor "Cisco" for product "Firepower Threat Defense" and version " < 6.4.0.10" | - |
Affected
| in | Cisco Search vendor "Cisco" | Firepower 1150 Search vendor "Cisco" for product "Firepower 1150" | - | - |
Safe
|
Cisco Search vendor "Cisco" | Firepower Threat Defense Search vendor "Cisco" for product "Firepower Threat Defense" | >= 6.5.0 < 6.5.0.5 Search vendor "Cisco" for product "Firepower Threat Defense" and version " >= 6.5.0 < 6.5.0.5" | - |
Affected
| in | Cisco Search vendor "Cisco" | Firepower 1000 Search vendor "Cisco" for product "Firepower 1000" | - | - |
Safe
|
Cisco Search vendor "Cisco" | Firepower Threat Defense Search vendor "Cisco" for product "Firepower Threat Defense" | >= 6.5.0 < 6.5.0.5 Search vendor "Cisco" for product "Firepower Threat Defense" and version " >= 6.5.0 < 6.5.0.5" | - |
Affected
| in | Cisco Search vendor "Cisco" | Firepower 1010 Search vendor "Cisco" for product "Firepower 1010" | - | - |
Safe
|
Cisco Search vendor "Cisco" | Firepower Threat Defense Search vendor "Cisco" for product "Firepower Threat Defense" | >= 6.5.0 < 6.5.0.5 Search vendor "Cisco" for product "Firepower Threat Defense" and version " >= 6.5.0 < 6.5.0.5" | - |
Affected
| in | Cisco Search vendor "Cisco" | Firepower 1120 Search vendor "Cisco" for product "Firepower 1120" | - | - |
Safe
|
Cisco Search vendor "Cisco" | Firepower Threat Defense Search vendor "Cisco" for product "Firepower Threat Defense" | >= 6.5.0 < 6.5.0.5 Search vendor "Cisco" for product "Firepower Threat Defense" and version " >= 6.5.0 < 6.5.0.5" | - |
Affected
| in | Cisco Search vendor "Cisco" | Firepower 1140 Search vendor "Cisco" for product "Firepower 1140" | - | - |
Safe
|
Cisco Search vendor "Cisco" | Firepower Threat Defense Search vendor "Cisco" for product "Firepower Threat Defense" | >= 6.5.0 < 6.5.0.5 Search vendor "Cisco" for product "Firepower Threat Defense" and version " >= 6.5.0 < 6.5.0.5" | - |
Affected
| in | Cisco Search vendor "Cisco" | Firepower 1150 Search vendor "Cisco" for product "Firepower 1150" | - | - |
Safe
|
Cisco Search vendor "Cisco" | Firepower Threat Defense Search vendor "Cisco" for product "Firepower Threat Defense" | >= 6.6.0 < 6.6.1 Search vendor "Cisco" for product "Firepower Threat Defense" and version " >= 6.6.0 < 6.6.1" | - |
Affected
| in | Cisco Search vendor "Cisco" | Firepower 1000 Search vendor "Cisco" for product "Firepower 1000" | - | - |
Safe
|
Cisco Search vendor "Cisco" | Firepower Threat Defense Search vendor "Cisco" for product "Firepower Threat Defense" | >= 6.6.0 < 6.6.1 Search vendor "Cisco" for product "Firepower Threat Defense" and version " >= 6.6.0 < 6.6.1" | - |
Affected
| in | Cisco Search vendor "Cisco" | Firepower 1010 Search vendor "Cisco" for product "Firepower 1010" | - | - |
Safe
|
Cisco Search vendor "Cisco" | Firepower Threat Defense Search vendor "Cisco" for product "Firepower Threat Defense" | >= 6.6.0 < 6.6.1 Search vendor "Cisco" for product "Firepower Threat Defense" and version " >= 6.6.0 < 6.6.1" | - |
Affected
| in | Cisco Search vendor "Cisco" | Firepower 1120 Search vendor "Cisco" for product "Firepower 1120" | - | - |
Safe
|
Cisco Search vendor "Cisco" | Firepower Threat Defense Search vendor "Cisco" for product "Firepower Threat Defense" | >= 6.6.0 < 6.6.1 Search vendor "Cisco" for product "Firepower Threat Defense" and version " >= 6.6.0 < 6.6.1" | - |
Affected
| in | Cisco Search vendor "Cisco" | Firepower 1140 Search vendor "Cisco" for product "Firepower 1140" | - | - |
Safe
|
Cisco Search vendor "Cisco" | Firepower Threat Defense Search vendor "Cisco" for product "Firepower Threat Defense" | >= 6.6.0 < 6.6.1 Search vendor "Cisco" for product "Firepower Threat Defense" and version " >= 6.6.0 < 6.6.1" | - |
Affected
| in | Cisco Search vendor "Cisco" | Firepower 1150 Search vendor "Cisco" for product "Firepower 1150" | - | - |
Safe
|
Cisco Search vendor "Cisco" | Adaptive Security Appliance Software Search vendor "Cisco" for product "Adaptive Security Appliance Software" | < 9.13.1.13 Search vendor "Cisco" for product "Adaptive Security Appliance Software" and version " < 9.13.1.13" | - |
Affected
| in | Cisco Search vendor "Cisco" | Firepower 1000 Search vendor "Cisco" for product "Firepower 1000" | - | - |
Safe
|
Cisco Search vendor "Cisco" | Adaptive Security Appliance Software Search vendor "Cisco" for product "Adaptive Security Appliance Software" | < 9.13.1.13 Search vendor "Cisco" for product "Adaptive Security Appliance Software" and version " < 9.13.1.13" | - |
Affected
| in | Cisco Search vendor "Cisco" | Firepower 1010 Search vendor "Cisco" for product "Firepower 1010" | - | - |
Safe
|
Cisco Search vendor "Cisco" | Adaptive Security Appliance Software Search vendor "Cisco" for product "Adaptive Security Appliance Software" | < 9.13.1.13 Search vendor "Cisco" for product "Adaptive Security Appliance Software" and version " < 9.13.1.13" | - |
Affected
| in | Cisco Search vendor "Cisco" | Firepower 1120 Search vendor "Cisco" for product "Firepower 1120" | - | - |
Safe
|
Cisco Search vendor "Cisco" | Adaptive Security Appliance Software Search vendor "Cisco" for product "Adaptive Security Appliance Software" | < 9.13.1.13 Search vendor "Cisco" for product "Adaptive Security Appliance Software" and version " < 9.13.1.13" | - |
Affected
| in | Cisco Search vendor "Cisco" | Firepower 1140 Search vendor "Cisco" for product "Firepower 1140" | - | - |
Safe
|
Cisco Search vendor "Cisco" | Adaptive Security Appliance Software Search vendor "Cisco" for product "Adaptive Security Appliance Software" | < 9.13.1.13 Search vendor "Cisco" for product "Adaptive Security Appliance Software" and version " < 9.13.1.13" | - |
Affected
| in | Cisco Search vendor "Cisco" | Firepower 1150 Search vendor "Cisco" for product "Firepower 1150" | - | - |
Safe
|
Cisco Search vendor "Cisco" | Adaptive Security Appliance Software Search vendor "Cisco" for product "Adaptive Security Appliance Software" | >= 9.14 < 9.14.1.30 Search vendor "Cisco" for product "Adaptive Security Appliance Software" and version " >= 9.14 < 9.14.1.30" | - |
Affected
| in | Cisco Search vendor "Cisco" | Firepower 1000 Search vendor "Cisco" for product "Firepower 1000" | - | - |
Safe
|
Cisco Search vendor "Cisco" | Adaptive Security Appliance Software Search vendor "Cisco" for product "Adaptive Security Appliance Software" | >= 9.14 < 9.14.1.30 Search vendor "Cisco" for product "Adaptive Security Appliance Software" and version " >= 9.14 < 9.14.1.30" | - |
Affected
| in | Cisco Search vendor "Cisco" | Firepower 1010 Search vendor "Cisco" for product "Firepower 1010" | - | - |
Safe
|
Cisco Search vendor "Cisco" | Adaptive Security Appliance Software Search vendor "Cisco" for product "Adaptive Security Appliance Software" | >= 9.14 < 9.14.1.30 Search vendor "Cisco" for product "Adaptive Security Appliance Software" and version " >= 9.14 < 9.14.1.30" | - |
Affected
| in | Cisco Search vendor "Cisco" | Firepower 1120 Search vendor "Cisco" for product "Firepower 1120" | - | - |
Safe
|
Cisco Search vendor "Cisco" | Adaptive Security Appliance Software Search vendor "Cisco" for product "Adaptive Security Appliance Software" | >= 9.14 < 9.14.1.30 Search vendor "Cisco" for product "Adaptive Security Appliance Software" and version " >= 9.14 < 9.14.1.30" | - |
Affected
| in | Cisco Search vendor "Cisco" | Firepower 1140 Search vendor "Cisco" for product "Firepower 1140" | - | - |
Safe
|
Cisco Search vendor "Cisco" | Adaptive Security Appliance Software Search vendor "Cisco" for product "Adaptive Security Appliance Software" | >= 9.14 < 9.14.1.30 Search vendor "Cisco" for product "Adaptive Security Appliance Software" and version " >= 9.14 < 9.14.1.30" | - |
Affected
| in | Cisco Search vendor "Cisco" | Firepower 1150 Search vendor "Cisco" for product "Firepower 1150" | - | - |
Safe
|