5
CVSSv2

CVE-2020-3283

Published: 06/05/2020 Updated: 17/09/2021
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
CVSS v3 Base Score: 8.6 | Impact Score: 4 | Exploitability Score: 3.9
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P

Vulnerability Summary

A vulnerability in the Secure Sockets Layer (SSL)/Transport Layer Security (TLS) handler of Cisco Firepower Threat Defense (FTD) Software when running on the Cisco Firepower 1000 Series platform could allow an unauthenticated, remote malicious user to trigger a denial of service (DoS) condition on an affected device. The vulnerability is due to a communication error between internal functions. An attacker could exploit this vulnerability by sending a crafted SSL/TLS message to an affected device. A successful exploit could allow the malicious user to cause a buffer underrun, which leads to a crash. The crash causes the affected device to reload.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

cisco firepower_threat_defense

cisco asa_5505_firmware 9.12\\(2.12\\)

cisco asa_5505_firmware 9.13\\(0.33\\)

cisco asa_5510_firmware 9.12\\(2.12\\)

cisco asa_5510_firmware 9.13\\(0.33\\)

cisco asa_5512-x_firmware 9.12\\(2.12\\)

cisco asa_5512-x_firmware 9.13\\(0.33\\)

cisco asa_5515-x_firmware 9.12\\(2.12\\)

cisco asa_5515-x_firmware 9.13\\(0.33\\)

cisco asa_5520_firmware 9.12\\(2.12\\)

cisco asa_5520_firmware 9.13\\(0.33\\)

cisco asa_5525-x_firmware 9.12\\(2.12\\)

cisco asa_5525-x_firmware 9.13\\(0.33\\)

cisco asa_5540_firmware 9.12\\(2.12\\)

cisco asa_5540_firmware 9.13\\(0.33\\)

cisco asa_5545-x_firmware 9.12\\(2.12\\)

cisco asa_5545-x_firmware 9.13\\(0.33\\)

cisco asa_5550_firmware 9.12\\(2.12\\)

cisco asa_5550_firmware 9.13\\(0.33\\)

cisco asa_5555-x_firmware 9.12\\(2.12\\)

cisco asa_5555-x_firmware 9.13\\(0.33\\)

cisco asa_5580_firmware 9.12\\(2.12\\)

cisco asa_5580_firmware 9.13\\(0.33\\)

cisco asa_5585-x_firmware 9.12\\(2.12\\)

cisco asa_5585-x_firmware 9.13\\(0.33\\)

Vendor Advisories

A vulnerability in the Secure Sockets Layer (SSL)/Transport Layer Security (TLS) handler of Cisco Firepower Threat Defense (FTD) Software when running on the Cisco Firepower 1000 Series platform could allow an unauthenticated, remote attacker to trigger a denial of service (DoS) condition on an affected device The vulnerability is due to a communi ...

Recent Articles

Bored at home? Cisco has just the thing: A shed-load of security fixes to install, from a Kerberos bypass to crashes
The Register • Shaun Nichols in San Francisco • 07 May 2020

Switchzilla issues a whopping 30+ patches in time for the long UK weekend

Cisco has emitted a fresh round of software updates to address nearly three dozen security holes in its products. The patches, released over May 6 and 7, include 12 issues considered high-severity bugs, and another 22 classified as moderate severity. One of the holes has two CVE numbers assigned to it, so that's a total of 35 CVE-listed security vulnerabilities. Despite the absence of a critical remote code or command execution bug, the patches include a number of serious programming blunders, p...