CVE-2020-3283
A vulnerability in the Secure Sockets Layer (SSL)/Transport Layer Security (TLS) handler of Cisco Firepower Threat Defense (FTD) Software when running on the Cisco Firepower 1000 Series platform could allow an unauthenticated, remote attacker to trigger a denial of service (DoS) condition on an affected device. The vulnerability is due to a communication error between internal functions. An attacker could exploit this vulnerability by sending a crafted SSL/TLS message to an affected device. A successful exploit could allow the attacker to cause a buffer underrun, which leads to a crash. The crash causes the affected device to reload.
EPSS 1.31% · 80.2th percentile
Risk Scores
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| cisco | asa_5515-x_firmware | 9.13\(0.33\), 9.12\(2.12\) |
| cisco | asa_5512-x_firmware | 9.12\(2.12\), 9.13\(0.33\) |
| cisco | asa_5555-x_firmware | *, 9.12\(2.12\) |
| cisco | asa_5585-x_firmware | 9.12\(2.12\), 9.13\(0.33\) |
| cisco | asa_5505_firmware | 9.12\(2.12\), 9.13\(0.33\) |
| Cisco | Cisco Firepower Threat Defense Software | * |
| cisco | asa_5545-x_firmware | 9.13\(0.33\), 9.12\(2.12\) |
| cisco | asa_5520_firmware | 9.12\(2.12\), 9.13\(0.33\) |
| cisco | asa_5540_firmware | 9.12\(2.12\), 9.13\(0.33\) |
| cisco | asa_5525-x_firmware | 9.12\(2.12\), 9.13\(0.33\) |
| cisco | asa_5580_firmware | 9.13\(0.33\), * |
| cisco | firepower_threat_defense | 6.4.0 |
| cisco | asa_5550_firmware | 9.13\(0.33\), 9.12\(2.12\) |
| cisco | asa_5510_firmware | 9.13\(0.33\), * |
Exploit Intelligence
Timeline
- May 6, 2020 CVE Published
- Apr 14, 2021 EPSS Score
- Jun 23, 2021 EPSS Score
- Sep 18, 2021 EPSS Score
- Oct 11, 2021 EPSS Score
- Oct 26, 2021 EPSS Score
- Jan 6, 2022 EPSS Score
- Feb 4, 2022 EPSS Score
- Feb 28, 2022 EPSS Score
- Apr 1, 2022 EPSS Score
- Jul 3, 2022 EPSS Score
- Sep 4, 2022 EPSS Score
References
- https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-asa-ssl-vpn-dos-qY7BHpjN advisory
- https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-asa-ftd-ospf-memleak-DHpsgfnv advisory
- https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ftd-dos-N2vQZASR advisory
- https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-asaftd-path-JE3azWw43 advisory
- https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-asa-ftd-ospf-dos-RhMQY8qx advisory
- https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ftd-dos-2-sS2h7aWe advisory
- https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ftd-dos-Rdpe34sd8 advisory
- https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-asaftd-mgcp-SUqB8VKH advisory
- https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-asa-kerberos-bypass-96Gghe2sS advisory
- 20200506 Cisco Firepower 1000 Series SSL/TLS Denial of Service Vulnerability vendor-advisory
- https://nvd.nist.gov/vuln/detail/CVE-2020-3283 advisory