CVE-2019-1687: Cisco Adaptive Security Appliance Software and Firepower Threat Defense Software TCP Proxy Denial of Service Vulnerability
A vulnerability in the TCP proxy functionality for Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause the device to restart unexpectedly, resulting in a denial of service (DoS) condition. The vulnerability is due to an error in TCP-based packet inspection, which could cause the TCP packet to have an invalid Layer 2 (L2)-formatted header. An attacker could exploit this vulnerability by sending a crafted TCP packet sequence to the targeted device. A successful exploit could allow the attacker to cause a DoS condition.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID?
The vulnerability ID is CVE-2019-1687.
What is the severity of CVE-2019-1687?
The severity of CVE-2019-1687 is high with a CVSS score of 7.5.
How does CVE-2019-1687 affect Cisco Adaptive Security Appliance (ASA) Software?
CVE-2019-1687 affects Cisco Adaptive Security Appliance (ASA) Software versions 9.4.4.34 up to but excluding 9.6.4.25, versions 9.7 up to but excluding 9.8.4, versions 9.9 up to but excluding 9.9.2.50, and versions 9.10 up to but excluding 9.10.1.17.
How does CVE-2019-1687 affect Cisco Firepower Threat Defense (FTD) Software?
CVE-2019-1687 affects Cisco Firepower Threat Defense (FTD) Software versions 6.0.0 up to but excluding 6.2.3.12, and versions 6.3.0 up to but excluding 6.3.0.3.
How can I fix CVE-2019-1687?
To fix CVE-2019-1687, Cisco recommends upgrading to a fixed software release.