CVE-2022-20927: High severity Cisco Adaptive Security Appliance Software vulnerability
A vulnerability in the SSL/TLS client of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an authenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to improper memory management when a device initiates SSL/TLS connections. An attacker could exploit this vulnerability by ensuring that the device will connect to an SSL/TLS server that is using specific encryption parameters. A successful exploit could allow the attacker to cause the affected device to unexpectedly reload, resulting in a DoS condition.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2022-20927?
CVE-2022-20927 is a vulnerability in the SSL/TLS client of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software that could allow an authenticated, remote attacker to cause a denial of service (DoS) condition on an affected device.
How does CVE-2022-20927 impact Cisco ASA Software?
CVE-2022-20927 can cause a denial of service (DoS) condition on Cisco ASA Software.
How does CVE-2022-20927 impact Cisco FTD Software?
CVE-2022-20927 can cause a denial of service (DoS) condition on Cisco Firepower Threat Defense (FTD) Software.
What is the severity of CVE-2022-20927?
CVE-2022-20927 has a severity rating of 6.5 (High).
Where can I find more information about CVE-2022-20927?
You can find more information about CVE-2022-20927 on the Cisco Security Advisory page: [link](https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ssl-client-dos-cCrQPkA)