First published: Wed Apr 20 2022(Updated: )
A vulnerability in the implementation of the Datagram TLS (DTLS) protocol in Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause high CPU utilization, resulting in a denial of service (DoS) condition. This vulnerability is due to suboptimal processing that occurs when establishing a DTLS tunnel as part of an AnyConnect SSL VPN connection. An attacker could exploit this vulnerability by sending a steady stream of crafted DTLS traffic to an affected device. A successful exploit could allow the attacker to exhaust resources on the affected VPN headend device. This could cause existing DTLS tunnels to stop passing traffic and prevent new DTLS tunnels from establishing, resulting in a DoS condition. Note: When the attack traffic stops, the device recovers gracefully. Cisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability. This advisory is available at the following link:https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-vpndtls-dos-TunzLEV
Credit: Fabio Streun ETH Zurich
Affected Software | Affected Version | How to fix |
---|---|---|
Cisco ASA Software | =9.17<9.17.1.10 (Jun 2022)>=9.15<=9.16<9.16.3.3>=9.13<=9.14<9.14.4.8 (Jun 2022)>=9.7 and earlier=9.8=9.9=9.10<=9.12<9.12.4.41 (Jun 2022) | 9.17.1.10 (Jun 2022) 9.16.3.3 9.14.4.8 (Jun 2022) 9.12.4.41 (Jun 2022) |
Cisco FTD Software | =7.1.0<7.1.0.3 (Oct 2022)>=6.7.0<=7.0.0<7.0.2 (May 2022)>=6.5.0<=6.6.0<6.6.7 (Jun 2022)>=6.2.2=6.2.3=6.3.0<=6.4.0<6.4.0.15 (May 2022) | 7.1.0.3 (Oct 2022) 7.0.2 (May 2022) 6.6.7 (Jun 2022) 6.4.0.15 (May 2022) |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is cisco-sa-vpndtls-dos-TunzLEV.
The title of this Cisco security advisory is 'Cisco Adaptive Security Appliance and Cisco Firepower Threat Defense Software AnyConnect SSL VPN Denial of Service Vulnerability'.
The severity of the vulnerability is medium with a CVSS score of 5.8.
Cisco ASA Software and Cisco FTD Software are affected by this vulnerability.
To fix this vulnerability, update to the recommended software versions.