---
id: CVE-2017-6625
title: >-
  A "Cisco Firepower Threat Defense 6.0.0 through 6.2.2 and Cisco ASA with
  FirePOWER Module Denial of Service" vulnerability in the access control policy
  of Cisco Firepower System Software could allow an authenticated, remote
  attacker to c…
summary: >-
  A "Cisco Firepower Threat Defense 6.0.0 through 6.2.2 and Cisco ASA with
  FirePOWER Module Denial of Service" vulnerability in the access control policy
  of Cisco Firepower System Software could allow an authenticated, remote
  attacker to c…
severity: high
cvss: 7.1
cvssVector: 'CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H'
cwe:
  - CWE-399
vendor: cisco
product: secure_firewall_threat_defense
affected:
  - secure_firewall_threat_defense = 6.0.0
  - secure_firewall_threat_defense = 6.0.1
  - secure_firewall_threat_defense = 6.1.0
  - secure_firewall_threat_defense = 6.1.0.2
  - secure_firewall_threat_defense = 6.2.0
  - secure_firewall_threat_defense = 6.2.1
  - secure_firewall_threat_defense = 6.2.2
published: '2017-05-03'
updated: '2026-08-11'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2017-6625'
references:
  - url: 'http://www.securityfocus.com/bid/98292'
    label: psirt@cisco.com
  - url: 'http://www.securitytracker.com/id/1038397'
    label: psirt@cisco.com
  - url: >-
      https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20170503-ftd
    label: psirt@cisco.com
  - url: 'http://www.securityfocus.com/bid/98292'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'http://www.securitytracker.com/id/1038397'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20170503-ftd
    label: af854a3a-2127-422b-91ae-364da2661108
tags:
  - nvd
epss: 0.01986
epssPercentile: 0.79468
ingestedAt: '2026-08-11T19:48:25.334Z'
---

## Overview

A "Cisco Firepower Threat Defense 6.0.0 through 6.2.2 and Cisco ASA with FirePOWER Module Denial of Service" vulnerability in the access control policy of Cisco Firepower System Software could allow an authenticated, remote attacker to cause an affected system to stop inspecting and processing packets, resulting in a denial of service (DoS) condition. The vulnerability is due to improper SSL policy handling by the affected software when packets are passed through the sensing interfaces of an affected system. An attacker could exploit this vulnerability by sending crafted packets through a targeted system. This vulnerability affects Cisco Firepower System Software that is configured with the SSL policy feature. Cisco Bug IDs: CSCvc84361.

## Affected

- `secure_firewall_threat_defense = 6.0.0`
- `secure_firewall_threat_defense = 6.0.1`
- `secure_firewall_threat_defense = 6.1.0`
- `secure_firewall_threat_defense = 6.1.0.2`
- `secure_firewall_threat_defense = 6.2.0`
- `secure_firewall_threat_defense = 6.2.1`
- `secure_firewall_threat_defense = 6.2.2`

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
