First published: Wed May 06 2020(Updated: )
A vulnerability in the DHCP module of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on the affected device. The vulnerability is due to incorrect processing of certain DHCP packets. An attacker could exploit this vulnerability by sending a crafted DHCP packet to the affected device. A successful exploit could allow the attacker to cause a DoS condition on the affected device.
Credit: ykramarz@cisco.com
Affected Software | Affected Version | How to fix |
---|---|---|
Cisco Adaptive Security Appliance Software | <9.6.4.34 | |
Cisco Adaptive Security Appliance Software | >=9.7<9.8.4.10 | |
Cisco Adaptive Security Appliance Software | >=9.9<9.10.1.30 | |
Cisco Adaptive Security Appliance Software | >=9.12<9.12.3 | |
Cisco ASA 5505 Firmware | ||
Cisco ASA 5510 firmware | ||
Cisco ASA 5512-X Firmware | ||
Cisco ASA 5515-X Firmware | ||
Cisco ASA Software | ||
Cisco ASA Software | ||
Cisco ASA 5550 firmware | ||
Cisco ASA 5555-X Firmware | ||
Cisco ASA 5580 Firmware | ||
Cisco ASA 5585-X | ||
Cisco Secure Firewall Threat Defense | <6.3.0.5 | |
Cisco Secure Firewall Threat Defense | >=6.4.0<6.4.0.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this vulnerability is CVE-2020-3306.
CVE-2020-3306 has a severity level of high.
CVE-2020-3306 affects Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software.
CVE-2020-3306 can cause a denial of service (DoS) condition on the affected device.
No, CVE-2020-3306 can be exploited by an unauthenticated, remote attacker.