Improper Check or Handling of Exceptional Conditions in Cisco Firewall Threat Defense (FTD) and Cisco Adaptive Security Appliance (ASA) - CVE-2022-20924

 

Improper Check or Handling of Exceptional Conditions in Cisco Firewall Threat Defense (FTD) and Cisco Adaptive Security Appliance (ASA) - CVE-2022-20924

Published: November 10, 2022


Vulnerability identifier: #VU69200
CSH Severity: Medium
CVSS v4: 7.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2022-20924
CWE-ID: CWE-703
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to insufficient validation of user-supplied input in the Simple Network Management Protocol (SNMP) feature. A remote user can send a specially crafted SNMP request and perform a denial of service (DoS) attack.


Affected software

Cisco Firewall Threat Defense (FTD)
Cisco Adaptive Security Appliance (ASA)

How to mitigate CVE-2022-20924

Install updates from vendor's website.

Cisco Firewall Threat Defense (FTD) - addressed in versions 006.006(007), 007.000(004), 007.002(001), 9.14.4.13, 009.014(004.013), 9.14.4.14, 9.14.4.15, 9.14.4.17, 009.016(003.015), 9.16.3.19, 9.16.3.23, 009.016(003.099), 009.016(004), 9.16.4, 009.017(001.017), 9.17.1.20, 009.018(001.003), 009.018(001.099), 9.18.2, 009.018(002), 9.18.2.5, 009.019(000.099), 099.014(004.026), 099.017(002.138), 099.018(002.027), 099.018(028.006), 099.018(030.074), 099.019(001.112), 099.019(021.034), 099.019(022.033), 099.019(023.030), 099.019(030.003), 099.020(000.002)
Cisco Adaptive Security Appliance (ASA) - addressed in versions 006.006(007), 007.000(004), 007.002(001), 9.14.4.13, 009.014(004.013), 9.14.4.14, 9.14.4.15, 9.14.4.17, 009.016(003.015), 9.16.3.19, 9.16.3.23, 009.016(003.099), 009.016(004), 9.16.4, 009.017(001.017), 9.17.1.20, 009.018(001.003), 009.018(001.099), 9.18.2, 009.018(002), 9.18.2.5, 009.019(000.099), 099.014(004.026), 099.017(002.138), 099.018(002.027), 099.018(028.006), 099.018(030.074), 099.019(001.112), 099.019(021.034), 099.019(022.033), 099.019(023.030), 099.019(030.003), 099.020(000.002)

External References

Related Security Bulletins