CVE-2020-3255: Cisco Firepower Threat Defense Software Packet Flood Denial of Service Vulnerability
A vulnerability in the packet processing functionality of Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. The vulnerability is due to inefficient memory management. An attacker could exploit this vulnerability by sending a high rate of IPv4 or IPv6 traffic through an affected device. This traffic would need to match a configured block action in an access control policy. An exploit could allow the attacker to cause a memory exhaustion condition on the affected device, which would result in a DoS for traffic transiting the device, as well as sluggish performance of the management interface. Once the flood is stopped, performance should return to previous states.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Compensating control
Mitigate the packet-flood DoS by blocking or filtering the high-rate IPv4/IPv6 traffic that matches an access control policy configured block action on affected Cisco Firepower Threat Defense (FTD) devices, so the flood traffic does not reach the packet processing functionality.
- Operational
After the flood activity is stopped, verify that device performance (including management interface responsiveness and traffic transit) returns to prior levels, since performance should return once the flood is stopped.
Event History
Frequently Asked Questions
What is the vulnerability ID of this Cisco Firepower Threat Defense (FTD) Software vulnerability?
The vulnerability ID of this Cisco Firepower Threat Defense (FTD) Software vulnerability is CVE-2020-3255.
What is the severity of CVE-2020-3255?
The severity of CVE-2020-3255 is high.
How does CVE-2020-3255 affect Cisco Firepower Threat Defense Software?
CVE-2020-3255 could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device running Cisco Firepower Threat Defense Software.
Which versions of Cisco Firepower Threat Defense Software are affected by CVE-2020-3255?
Versions 6.2.3 to 6.2.3.16, 6.3.0 to 6.3.0.6, and 6.4.0 to 6.4.0.9 of Cisco Firepower Threat Defense Software are affected by CVE-2020-3255.
How can I fix CVE-2020-3255?
To fix CVE-2020-3255, Cisco recommends upgrading to a fixed software release.