Lucene search

K
nvd[email protected]NVD:CVE-2020-3529
HistoryOct 21, 2020 - 7:15 p.m.

CVE-2020-3529

2020-10-2119:15:16
CWE-400
web.nvd.nist.gov
6
ssl vpn negotiation
cisco asa
cisco ftd
dos condition
dma memory management

CVSS2

5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:N/I:N/A:P

CVSS3

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

EPSS

0.002

Percentile

52.6%

A vulnerability in the SSL VPN negotiation process for Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause a reload of an affected device, resulting in a denial of service (DoS) condition. The vulnerability is due to inefficient direct memory access (DMA) memory management during the negotiation phase of an SSL VPN connection. An attacker could exploit this vulnerability by sending a steady stream of crafted Datagram TLS (DTLS) traffic to an affected device. A successful exploit could allow the attacker to exhaust DMA memory on the device and cause a DoS condition.

Affected configurations

Nvd
Node
ciscoadaptive_security_applianceRange<9.6.4.45
OR
ciscofirepower_threat_defenseRange<6.3.0.6
OR
ciscofirepower_threat_defenseRange6.4.06.4.0.10
OR
ciscofirepower_threat_defenseRange6.5.06.5.0.5
OR
ciscofirepower_threat_defenseRange6.6.06.6.1
OR
ciscoadaptive_security_appliance_softwareRange9.8.09.8.4.29
OR
ciscoadaptive_security_appliance_softwareRange9.9.09.9.2.80
OR
ciscoadaptive_security_appliance_softwareRange9.10.09.10.1.44
OR
ciscoadaptive_security_appliance_softwareRange9.12.09.12.4.4
OR
ciscoadaptive_security_appliance_softwareRange9.13.09.13.1.13
OR
ciscoadaptive_security_appliance_softwareRange9.14.09.14.1.30
VendorProductVersionCPE
ciscoadaptive_security_appliance*cpe:2.3:a:cisco:adaptive_security_appliance:*:*:*:*:*:*:*:*
ciscofirepower_threat_defense*cpe:2.3:a:cisco:firepower_threat_defense:*:*:*:*:*:*:*:*
ciscoadaptive_security_appliance_software*cpe:2.3:o:cisco:adaptive_security_appliance_software:*:*:*:*:*:*:*:*

CVSS2

5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:N/I:N/A:P

CVSS3

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

EPSS

0.002

Percentile

52.6%

Related for NVD:CVE-2020-3529