CVE-2022-20950: Medium severity Cisco Firepower Threat Defense vulnerability
A vulnerability in the interaction of SIP and Snort 3 for Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause the Snort 3 detection engine to restart. This vulnerability is due to a lack of error-checking when SIP bidirectional flows are being inspected by Snort 3. An attacker could exploit this vulnerability by sending a stream of crafted SIP traffic through an interface on the targeted device. A successful exploit could allow the attacker to trigger a restart of the Snort 3 process, resulting in a denial of service (DoS) condition.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the vulnerability ID?
The vulnerability ID is CVE-2022-20950.
What software is affected by this vulnerability?
Cisco Firepower Threat Defense (FTD) Software versions 7.2.0 and 7.2.0.1 are affected.
How severe is this vulnerability?
The severity of this vulnerability is medium with a CVSS score of 5.3.
How can an attacker exploit this vulnerability?
An unauthenticated, remote attacker can exploit this vulnerability to cause the Snort 3 detection engine to restart.
Is there a fix or patch available?
Please refer to the Cisco Security Advisory for information on available fixes or patches.