A vulnerability in the Secure Sockets Layer (SSL)/Transport Layer Security (TLS) handler of Cisco Firepower Threat Defense (FTD) Software when running on the Cisco Firepower 1000 Series platform could allow an unauthenticated, remote attacker to trigger a denial of service (DoS) condition on an affected device. The vulnerability is due to a communication error between internal functions. An attacker could exploit this vulnerability by sending a crafted SSL/TLS message to an affected device. A successful exploit could allow the attacker to cause a buffer underrun, which leads to a crash. The crash causes the affected device to reload.
AI analysis not yet available
Plain-English explanation, risk summary, and remediation steps will appear here once AI analysis is complete.
No Fix Known
No patch has been released yet. Apply workarounds or mitigations where available.
| Vendor | Product | Versions | Fixed In |
|---|---|---|---|
| cisco | firepower_threat_defense | 6.4.0 - 6.4.0.9 | - |
| cisco | asa_5505_firmware | - |
Published
CVE disclosed publicly
Last Modified
Most recent update
Indexed to CVEInsight
Added to this platform
AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H
25
Affected Products
2
References
cisco / firepower_threat_defense
| - |
| cisco | asa_5505_firmware | - | - |
| cisco | asa_5510_firmware | - | - |
| cisco | asa_5510_firmware | - | - |
| cisco | asa_5512-x_firmware | - | - |
| cisco | asa_5512-x_firmware | - | - |
| cisco | asa_5515-x_firmware | - | - |
| cisco | asa_5515-x_firmware | - | - |
| cisco | asa_5520_firmware | - | - |
| cisco | asa_5520_firmware | - | - |
| cisco | asa_5525-x_firmware | - | - |
| cisco | asa_5525-x_firmware | - | - |
| cisco | asa_5540_firmware | - | - |
| cisco | asa_5540_firmware | - | - |
| cisco | asa_5545-x_firmware | - | - |
| cisco | asa_5545-x_firmware | - | - |
| cisco | asa_5550_firmware | - | - |
| cisco | asa_5550_firmware | - | - |
| cisco | asa_5555-x_firmware | - | - |
| cisco | asa_5555-x_firmware | - | - |
| cisco | asa_5580_firmware | - | - |
| cisco | asa_5580_firmware | - | - |
| cisco | asa_5585-x_firmware | - | - |
| cisco | asa_5585-x_firmware | - | - |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H
Exploitability
Impact