cisco-sa-ftd-mgmt-interface-dos-FkG4MuTU: Cisco Firepower Threat Defense Software Management Interface Denial of Service Vulnerability
A vulnerability in how Cisco Firepower Threat Defense (FTD) Software handles session timeouts for management connections could allow an unauthenticated, remote attacker to cause a buildup of remote management connections to an affected device, which could result in a denial of service (DoS) condition. The vulnerability exists because the default session timeout period for specific to-the-box remote management connections is too long. An attacker could exploit this vulnerability by sending a large and sustained number of crafted remote management connections to an affected device, resulting in a buildup of those connections over time. A successful exploit could allow the attacker to cause the remote management interface or Cisco Firepower Device Manager (FDM) to stop responding and cause other management functions to go offline, resulting in a DoS condition. The user traffic that is flowing through the device would not be affected, and the DoS condition would be isolated to remote management only. There are no workarounds that address this vulnerability. This advisory is available at the following link:https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ftd-mgmt-interface-dos-FkG4MuTU
Credit
Affected Software
Event History
Frequently Asked Questions
What is the severity of cisco-sa-ftd-mgmt-interface-dos-FkG4MuTU?
The severity of cisco-sa-ftd-mgmt-interface-dos-FkG4MuTU is critical due to its potential to cause denial of service by overwhelming management connections.
How do I fix cisco-sa-ftd-mgmt-interface-dos-FkG4MuTU?
To fix cisco-sa-ftd-mgmt-interface-dos-FkG4MuTU, upgrade to the recommended versions of Cisco FTD Software, specifically 6.5.0.5 or later.
Who is affected by cisco-sa-ftd-mgmt-interface-dos-FkG4MuTU?
Cisco Firepower Threat Defense Software versions earlier than 6.5.0.5 are affected by cisco-sa-ftd-mgmt-interface-dos-FkG4MuTU.
What type of attack does cisco-sa-ftd-mgmt-interface-dos-FkG4MuTU allow?
cisco-sa-ftd-mgmt-interface-dos-FkG4MuTU allows an unauthenticated remote attacker to create a buildup of management connections, leading to denial of service.
Is authentication required to exploit cisco-sa-ftd-mgmt-interface-dos-FkG4MuTU?
No, authentication is not required to exploit cisco-sa-ftd-mgmt-interface-dos-FkG4MuTU, making it particularly dangerous.