CVE-2020-3317: Cisco Firepower Threat Defense Software SSL Input Validation Denial of Service Vulnerability
A vulnerability in the sslinspection component of Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to crash Snort instances. The vulnerability is due to insufficient input validation in the sslinspection component. An attacker could exploit this vulnerability by sending a malformed TLS packet through a Cisco Adaptive Security Appliance (ASA). A successful exploit could allow the attacker to crash a Snort instance, resulting in a denial of service (DoS) condition.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID for this Cisco Firepower Threat Defense (FTD) Software vulnerability?
The vulnerability ID for this Cisco Firepower Threat Defense (FTD) Software vulnerability is CVE-2020-3317.
What is the severity of CVE-2020-3317?
The severity of CVE-2020-3317 is high with a CVSS score of 7.5.
What component of Cisco Firepower Threat Defense (FTD) Software is affected by CVE-2020-3317?
The ssl_inspection component of Cisco Firepower Threat Defense (FTD) Software is affected by CVE-2020-3317.
How can an attacker exploit CVE-2020-3317?
An attacker can exploit CVE-2020-3317 by sending malicious input to the ssl_inspection component, leading to a crash in Snort instances.
How can I fix CVE-2020-3317?
To fix CVE-2020-3317, it is recommended to update to a version of Cisco Firepower Threat Defense (FTD) Software that is not affected by the vulnerability.