Resource management error in Cisco Firewall Threat Defense (FTD) - CVE-2022-20949

 

Resource management error in Cisco Firewall Threat Defense (FTD) - CVE-2022-20949

Published: November 10, 2022


Vulnerability identifier: #VU69205
CSH Severity: Low
CVSS v4: 7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2022-20949
CWE-ID: CWE-399
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to compromise the target system.

The vulnerability exists due to improper management of internal resources within the application in the management web server. A remote administrator can send specially crafted messages to the affected HTTPS handler and perform configuration changes on the affected system.


Affected software

Cisco Firewall Threat Defense (FTD)

How to mitigate CVE-2022-20949

Install updates from vendor's website.

Cisco Firewall Threat Defense (FTD) - addressed in versions 006.006(007), 007.000(004), 007.002(001), 009.008(004.046), 009.012(004.051), 9.12.4.52, 9.14.4.13, 009.014(004.013), 9.14.4.14, 009.016(003.016), 9.16.3.19, 9.16.3.23, 009.016(003.099), 009.016(004), 009.017(001.017), 009.018(001.099), 009.018(002), 9.18.2, 009.019(000.099), 099.014(004.027), 099.017(002.139), 099.018(002.032), 099.019(001.129), 099.019(021.038), 099.019(022.035), 099.020(000.006)

External References

Related Security Bulletins