CVE-2020-3303
גבוהה 7.5
תיאור (מקור, אנגלית)
A vulnerability in the Internet Key Exchange version 1 (IKEv1) feature of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition. The vulnerability is due to improper management of system memory. An attacker could exploit this vulnerability by sending malicious IKEv1 traffic to an affected device. A successful exploit could allow the attacker to cause a DoS condition on the affected device.
מדדים
- CVSS 3.1
-
7.5 (HIGH)
מקור הציון: NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H - CWE
- CWE-399, CWE-400
מוצרים מושפעים
cisco: adaptive security appliance; cisco: adaptive security appliance software; cisco: asa 5505; cisco: asa 5510; cisco: asa 5512-x; cisco: asa 5515-x; cisco: asa 5520; cisco: asa 5525-x; cisco: asa 5550; cisco: asa 5555-x; cisco: asa 5580; cisco: asa 5585-x; cisco: secure firewall threat defense