Buffer overflow in Cisco Firewall Threat Defense (FTD) and Cisco Adaptive Security Appliance (ASA) - CVE-2022-20947
Published: November 10, 2022
Vulnerability identifier: #VU69202
CSH Severity: High
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2022-20947
CWE-ID: CWE-119
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to a boundary error in dynamic access policies (DAP) functionality. A remote attacker can trigger memory corruption and cause a denial of service condition on the target system.
Affected software
Cisco Firewall Threat Defense (FTD)
Cisco Adaptive Security Appliance (ASA)
Cisco Adaptive Security Appliance (ASA)
How to mitigate CVE-2022-20947
Install updates from vendor's website.
Cisco Firewall Threat Defense (FTD) - addressed in versions 006.004(000.015), 006.006(007), 007.000(002), 007.002(000), 009.008(004.044), 9.8.4.45, 9.8.4.46, 9.12.4.48, 9.12.4.50, 9.12.4.52, 9.12.4.54, 9.14.4, 9.14.4.13, 9.14.4.14, 9.14.4.15, 9.14.4.17, 9.16.3, 9.16.3.19, 9.16.3.23, 9.16.4, 9.17.1.13, 9.17.1.15, 9.17.1.20, 009.018(001), 9.18.1, 9.18.2, 9.18.2.5
Cisco Adaptive Security Appliance (ASA) - addressed in versions 006.004(000.015), 006.006(007), 007.000(002), 007.002(000), 009.008(004.044), 9.8.4.45, 9.8.4.46, 9.12.4.48, 9.12.4.50, 9.12.4.52, 9.12.4.54, 9.14.4, 9.14.4.13, 9.14.4.14, 9.14.4.15, 9.14.4.17, 9.16.3, 9.16.3.19, 9.16.3.23, 9.16.4, 9.17.1.13, 9.17.1.15, 9.17.1.20, 009.018(001), 9.18.1, 9.18.2, 9.18.2.5
Cisco Adaptive Security Appliance (ASA) - addressed in versions 006.004(000.015), 006.006(007), 007.000(002), 007.002(000), 009.008(004.044), 9.8.4.45, 9.8.4.46, 9.12.4.48, 9.12.4.50, 9.12.4.52, 9.12.4.54, 9.14.4, 9.14.4.13, 9.14.4.14, 9.14.4.15, 9.14.4.17, 9.16.3, 9.16.3.19, 9.16.3.23, 9.16.4, 9.17.1.13, 9.17.1.15, 9.17.1.20, 009.018(001), 9.18.1, 9.18.2, 9.18.2.5