Observable discrepancy in Cisco Firewall Threat Defense (FTD) - CVE-2022-20940
Published: November 10, 2022
Vulnerability identifier: #VU69204
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2022-20940
CWE-ID: CWE-203
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to gain access to potentially sensitive information.
The vulnerability exists due to observable discrepancy issue in the TLS handler. A remote attacker can send specially crafted TLS messages and gain unauthorized access to sensitive information on the system.
Affected software
Cisco Firewall Threat Defense (FTD)
How to mitigate CVE-2022-20940
Install updates from vendor's website.
Cisco Firewall Threat Defense (FTD) - addressed in versions 006.004(000.015), 006.006(007), 007.000(004), 007.002(000), 9.12.4.48, 9.12.4.50, 9.12.4.52, 9.14.4.13, 9.14.4.14, 009.016(003.012), 9.16.3.19, 9.16.3.23, 009.016(003.099), 009.016(004), 9.16.4, 009.017(001.010), 9.17.1.11, 9.17.1.13, 9.17.1.15, 009.018(001), 9.18.1, 9.18.1.3, 9.18.2, 9.18.2.5, 009.019(000.099), 099.017(028.079), 099.019(030.002)