CVE-2020-3571: Cisco Firepower 4110 ICMP Flood Denial of Service Vulnerability
A vulnerability in the ICMP ingress packet processing of Cisco Firepower Threat Defense (FTD) Software for Cisco Firepower 4110 appliances could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. The vulnerability is due to incomplete input validation upon receiving ICMP packets. An attacker could exploit this vulnerability by sending a high number of crafted ICMP or ICMPv6 packets to an affected device. A successful exploit could allow the attacker to cause a memory exhaustion condition that may result in an unexpected reload. No manual intervention is needed to recover the device after the reload.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2020-3571?
CVE-2020-3571 is a vulnerability in the ICMP ingress packet processing of Cisco Firepower Threat Defense (FTD) Software for Cisco Firepower 4110 appliances.
How does CVE-2020-3571 affect Cisco Firepower Threat Defense?
CVE-2020-3571 allows an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device.
What is the severity of CVE-2020-3571?
CVE-2020-3571 has a severity value of 8.6, which is considered high.
Which versions of Cisco Firepower Threat Defense are affected by CVE-2020-3571?
CVE-2020-3571 affects Cisco Firepower Threat Defense versions 6.3.0 through 6.5.0.
How can I fix CVE-2020-3571?
To fix CVE-2020-3571, it is recommended to upgrade to a version of Cisco Firepower Threat Defense that is not affected by the vulnerability.