First published: Wed May 06 2020(Updated: )
A vulnerability in the Internet Key Exchange version 1 (IKEv1) feature of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition. The vulnerability is due to improper management of system memory. An attacker could exploit this vulnerability by sending malicious IKEv1 traffic to an affected device. A successful exploit could allow the attacker to cause a DoS condition on the affected device.
Credit: ykramarz@cisco.com ykramarz@cisco.com
Affected Software | Affected Version | How to fix |
---|---|---|
Cisco Adaptive Security Appliance | <9.6.4.36 | |
Cisco Adaptive Security Appliance Software | >=9.7<9.8.4.10 | |
Cisco Adaptive Security Appliance Software | >=9.9<9.10.1.30 | |
Cisco Adaptive Security Appliance Software | >=9.12<9.12.2.9 | |
Cisco Asa 5505 | ||
Cisco Asa 5510 | ||
Cisco Asa 5512-x | ||
Cisco Asa 5515-x | ||
Cisco Asa 5520 | ||
Cisco Asa 5525-x | ||
Cisco Asa 5550 | ||
Cisco Asa 5555-x | ||
Cisco Asa 5580 | ||
Cisco Asa 5585-x | ||
Cisco Firepower Threat Defense | <6.3.0.5 | |
Cisco Firepower Threat Defense | >=6.4.0<6.4.0.6 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-3303 is a vulnerability in the Internet Key Exchange version 1 (IKEv1) feature of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software that could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition.
The vulnerability affects Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software.
The severity of CVE-2020-3303 is high, with a severity value of 7.5.
An unauthenticated, remote attacker can exploit CVE-2020-3303 by sending specially crafted IKEv1 packets to the affected software, causing a denial of service (DoS) condition.
Yes, Cisco has released software updates to address the vulnerability. It is recommended to install the latest updates provided by Cisco.