Observable discrepancy in Cisco Firewall Threat Defense (FTD) - CVE-2022-20940

 

Observable discrepancy in Cisco Firewall Threat Defense (FTD) - CVE-2022-20940

Published: November 10, 2022


Vulnerability identifier: #VU69204
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2022-20940
CWE-ID: CWE-203
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to gain access to potentially sensitive information.

The vulnerability exists due to observable discrepancy issue in the TLS handler. A remote attacker can send specially crafted TLS messages and gain unauthorized access to sensitive information on the system.


Affected software

Cisco Firewall Threat Defense (FTD)

How to mitigate CVE-2022-20940

Install updates from vendor's website.

Cisco Firewall Threat Defense (FTD) - addressed in versions 006.004(000.015), 006.006(007), 007.000(004), 007.002(000), 9.12.4.48, 9.12.4.50, 9.12.4.52, 9.14.4.13, 9.14.4.14, 009.016(003.012), 9.16.3.19, 9.16.3.23, 009.016(003.099), 009.016(004), 9.16.4, 009.017(001.010), 9.17.1.11, 9.17.1.13, 9.17.1.15, 009.018(001), 9.18.1, 9.18.1.3, 9.18.2, 9.18.2.5, 009.019(000.099), 099.017(028.079), 099.019(030.002)

External References

Related Security Bulletins