← לוח פגיעויות

CVE-2020-3283

גבוהה 8.6

תיאור (מקור, אנגלית)

A vulnerability in the Secure Sockets Layer (SSL)/Transport Layer Security (TLS) handler of Cisco Firepower Threat Defense (FTD) Software when running on the Cisco Firepower 1000 Series platform could allow an unauthenticated, remote attacker to trigger a denial of service (DoS) condition on an affected device. The vulnerability is due to a communication error between internal functions. An attacker could exploit this vulnerability by sending a crafted SSL/TLS message to an affected device. A successful exploit could allow the attacker to cause a buffer underrun, which leads to a crash. The crash causes the affected device to reload.

מדדים

CVSS 3.1
8.6 (HIGH) מקור הציון: NVD CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H
CWE
CWE-119, CWE-787

מוצרים מושפעים

cisco: secure firewall threat defense; cisco: firepower 1010; cisco: firepower 1020; cisco: firepower 1030; cisco: firepower 1040; cisco: asa 5505 firmware; cisco: asa 5505; cisco: asa 5510 firmware; cisco: asa 5510; cisco: asa 5512-x firmware; cisco: asa 5512-x; cisco: asa 5515-x firmware; cisco: asa 5515-x; cisco: asa 5520 firmware; cisco: asa 5520

קישורים