Buffer overflow in Cisco Firewall Threat Defense (FTD) and Cisco Adaptive Security Appliance (ASA) - CVE-2022-20947

 

Buffer overflow in Cisco Firewall Threat Defense (FTD) and Cisco Adaptive Security Appliance (ASA) - CVE-2022-20947

Published: November 10, 2022


Vulnerability identifier: #VU69202
CSH Severity: High
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2022-20947
CWE-ID: CWE-119
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to a boundary error in dynamic access policies (DAP) functionality. A remote attacker can trigger memory corruption and cause a denial of service condition on the target system.


Affected software

Cisco Firewall Threat Defense (FTD)
Cisco Adaptive Security Appliance (ASA)

How to mitigate CVE-2022-20947

Install updates from vendor's website.

Cisco Firewall Threat Defense (FTD) - addressed in versions 006.004(000.015), 006.006(007), 007.000(002), 007.002(000), 009.008(004.044), 9.8.4.45, 9.8.4.46, 9.12.4.48, 9.12.4.50, 9.12.4.52, 9.12.4.54, 9.14.4, 9.14.4.13, 9.14.4.14, 9.14.4.15, 9.14.4.17, 9.16.3, 9.16.3.19, 9.16.3.23, 9.16.4, 9.17.1.13, 9.17.1.15, 9.17.1.20, 009.018(001), 9.18.1, 9.18.2, 9.18.2.5
Cisco Adaptive Security Appliance (ASA) - addressed in versions 006.004(000.015), 006.006(007), 007.000(002), 007.002(000), 009.008(004.044), 9.8.4.45, 9.8.4.46, 9.12.4.48, 9.12.4.50, 9.12.4.52, 9.12.4.54, 9.14.4, 9.14.4.13, 9.14.4.14, 9.14.4.15, 9.14.4.17, 9.16.3, 9.16.3.19, 9.16.3.23, 9.16.4, 9.17.1.13, 9.17.1.15, 9.17.1.20, 009.018(001), 9.18.1, 9.18.2, 9.18.2.5

External References

Related Security Bulletins