---
id: CVE-2019-1687
title: >-
  A vulnerability in the TCP proxy functionality for Cisco Adaptive Security
  Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software
  could allow an unauthenticated, remote attacker to cause the device to restart
  unexpect…
summary: >-
  A vulnerability in the TCP proxy functionality for Cisco Adaptive Security
  Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software
  could allow an unauthenticated, remote attacker to cause the device to restart
  unexpect…
severity: high
cvss: 7.5
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'
cwe:
  - CWE-20
  - CWE-20
vendor: cisco
product: adaptive_security_appliance_software
affected:
  - adaptive_security_appliance_software < 9.4.4.34
  - 'adaptive_security_appliance_software >= 9.5, < 9.6.4.25'
  - 'adaptive_security_appliance_software >= 9.7, < 9.8.4'
  - 'adaptive_security_appliance_software >= 9.9, < 9.9.2.50'
  - 'adaptive_security_appliance_software >= 9.10, < 9.10.1.17'
  - 'secure_firewall_threat_defense >= 6.0.0, < 6.2.3.12'
  - 'secure_firewall_threat_defense >= 6.3.0, < 6.3.0.3'
patched:
  - adaptive_security_appliance_software 9.10.1.17
  - secure_firewall_threat_defense 6.3.0.3
published: '2019-05-03'
updated: '2026-08-11'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2019-1687'
references:
  - url: 'http://www.securityfocus.com/bid/108176'
    label: psirt@cisco.com
  - url: >-
      https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20190501-asa-ftdtcp-dos
    label: psirt@cisco.com
  - url: 'http://www.securityfocus.com/bid/108176'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20190501-asa-ftdtcp-dos
    label: af854a3a-2127-422b-91ae-364da2661108
tags:
  - nvd
epss: 0.029
epssPercentile: 0.86365
ingestedAt: '2026-08-11T19:48:26.144Z'
---

## Overview

A vulnerability in the TCP proxy functionality for Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause the device to restart unexpectedly, resulting in a denial of service (DoS) condition. The vulnerability is due to an error in TCP-based packet inspection, which could cause the TCP packet to have an invalid Layer 2 (L2)-formatted header. An attacker could exploit this vulnerability by sending a crafted TCP packet sequence to the targeted device. A successful exploit could allow the attacker to cause a DoS condition.

## Affected

- `adaptive_security_appliance_software < 9.4.4.34`
- `adaptive_security_appliance_software >= 9.5, < 9.6.4.25`
- `adaptive_security_appliance_software >= 9.7, < 9.8.4`
- `adaptive_security_appliance_software >= 9.9, < 9.9.2.50`
- `adaptive_security_appliance_software >= 9.10, < 9.10.1.17`
- `secure_firewall_threat_defense >= 6.0.0, < 6.2.3.12`
- `secure_firewall_threat_defense >= 6.3.0, < 6.3.0.3`

## Remediation

Upgrade past the affected range:

- `adaptive_security_appliance_software 9.10.1.17`
- `secure_firewall_threat_defense 6.3.0.3`
