Resource management error in Cisco Adaptive Security Appliance (ASA) and Cisco Firewall Threat Defense (FTD) - CVE-2020-3334

 

Resource management error in Cisco Adaptive Security Appliance (ASA) and Cisco Firewall Threat Defense (FTD) - CVE-2020-3334

Published: May 11, 2020


Vulnerability identifier: #VU27687
CSH Severity: Low
CVSS v4: 7.1 [CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2020-3334
CWE-ID: CWE-399
Exploitation vector: Adjecent network
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to incorrect processing of ARP packets received by the management interface. A remote attacker on the local network can pass specially crafted data to the application and perform a denial of service (DoS) attack.

Note: This vulnerability affects Cisco Firepower Threat Defense (FTD) Software for Cisco Firepower 2100 Series Security Appliances.


Affected software

Cisco Adaptive Security Appliance (ASA)
Cisco Firewall Threat Defense (FTD)

How to mitigate CVE-2020-3334

Install updates from vendor's website.

Cisco Adaptive Security Appliance (ASA) - addressed in versions 9.10.1.37, 9.12.3, 9.13.1.2
Cisco Firewall Threat Defense (FTD) - update to 6.6.0

External References

Related Security Bulletins