CVE-2022-20746: Cisco Firepower Threat Defense Software TCP Proxy Denial of Service Vulnerability
A vulnerability in the TCP proxy functionality of Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to trigger a denial of service (DoS) condition. This vulnerability is due to improper handling of TCP flows. An attacker could exploit this vulnerability by sending a crafted stream of TCP traffic through an affected device. A successful exploit could allow the attacker to cause the device to reload, resulting in a DoS condition.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2022-20746?
CVE-2022-20746 is a vulnerability in the TCP proxy functionality of Cisco Firepower Threat Defense (FTD) Software that could allow an unauthenticated, remote attacker to trigger a denial of service (DoS) condition.
How does CVE-2022-20746 affect Cisco Firepower Threat Defense Software?
CVE-2022-20746 affects Cisco Firepower Threat Defense (FTD) Software versions 6.4.0.15, 6.5.0 to 6.6.5.2, and 7.0.0 to 7.0.2, as well as version 7.1.0.
What is the severity of CVE-2022-20746?
CVE-2022-20746 has a severity rating of 7.5 (high).
How can an attacker exploit CVE-2022-20746?
An attacker can exploit CVE-2022-20746 by triggering a denial of service (DoS) condition through improper handling of TCP flows.
Is there a fix available for CVE-2022-20746?
To fix CVE-2022-20746, it is recommended to upgrade to a version of Cisco Firepower Threat Defense (FTD) Software that is not affected by the vulnerability.