cisco-sa-asa-ftd-ospf-dos-RhMQY8qx: Cisco Adaptive Security Appliance Software and Firepower Threat Defense Software Malformed OSPF Packets Processing Denial of Service Vulnerability
A vulnerability in the Open Shortest Path First (OSPF) implementation of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause the reload of an affected device, resulting in a denial of service (DoS) condition. The vulnerability is due to improper memory protection mechanisms while processing certain OSPF packets. An attacker could exploit this vulnerability by sending a series of malformed OSPF packets in a short period of time to an affected device. A successful exploit could allow the attacker to cause a reload of the affected device, resulting in a DoS condition for client traffic that is traversing the device. Cisco has released software updates that address the vulnerability described in this advisory. There are no workarounds that address this vulnerability. This advisory is available at the following link:https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-asa-ftd-ospf-dos-RhMQY8qx This advisory is part of the May 2020 Cisco ASA, FMC, and FTD Software Security Advisory Bundled Publication, which includes 12 Cisco Security Advisories that describe 12 vulnerabilities. For a complete list of the advisories and links to them, see Cisco Event Response: May 2020 Cisco ASA, FMC, and FTD Software Security Advisory Bundled Publication.
Credit
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID for this Cisco ASA and FTD software vulnerability?
The vulnerability ID for this Cisco ASA and FTD software vulnerability is cisco-sa-asa-ftd-ospf-dos-RhMQY8qx.
What is the severity rating of the Cisco ASA and FTD software vulnerability?
The severity rating of the Cisco ASA and FTD software vulnerability is 8.6 (high).
Which versions of Cisco ASA Software are affected by this vulnerability?
The affected versions of Cisco ASA Software are 9.13 up to exclusive 9.13.1.7, 9.12 up to exclusive 9.12.3.7, 9.10 up to exclusive 9.10.1.37, 9.9 up to exclusive 9.9.2.66, 9.7 up to inclusive 9.8, and 9.6 up to exclusive 9.6.4.40.
Which versions of Cisco FTD Software are affected by this vulnerability?
The affected versions of Cisco FTD Software are 6.4.0 up to inclusive 6.5.0, and 6.2.3 up to exclusive 6.2.3.16 (June 2020).
How can I fix the Cisco ASA and FTD software vulnerability?
To fix the Cisco ASA and FTD software vulnerability, apply the recommended remediation or update provided by Cisco based on your specific affected software version.