---
id: CVE-2020-3179
title: >-
  A vulnerability in the generic routing encapsulation (GRE) tunnel
  decapsulation feature of Cisco Firepower Threat Defense (FTD) Software could
  allow an unauthenticated, remote attacker to cause a denial of service (DoS)
  condition on an a…
summary: >-
  A vulnerability in the generic routing encapsulation (GRE) tunnel
  decapsulation feature of Cisco Firepower Threat Defense (FTD) Software could
  allow an unauthenticated, remote attacker to cause a denial of service (DoS)
  condition on an a…
severity: high
cvss: 7.5
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'
cwe:
  - CWE-415
  - CWE-415
vendor: cisco
product: secure_firewall_threat_defense
affected:
  - 'secure_firewall_threat_defense >= 6.3.0, < 6.3.0.5'
  - 'secure_firewall_threat_defense >= 6.4.0, < 6.4.0.6'
  - asa_5505_firmware = 9.9(2)
  - asa_5505_firmware = 101.5(1.26)
  - asa_5510_firmware = 9.9(2)
  - asa_5510_firmware = 101.5(1.26)
  - asa_5512-x_firmware = 9.9(2)
  - asa_5512-x_firmware = 101.5(1.26)
  - asa_5515-x_firmware = 9.9(2)
  - asa_5515-x_firmware = 101.5(1.26)
  - asa_5520_firmware = 9.9(2)
  - asa_5520_firmware = 101.5(1.26)
  - asa_5525-x_firmware = 9.9(2)
  - asa_5525-x_firmware = 101.5(1.26)
  - asa_5540_firmware = 9.9(2)
  - asa_5540_firmware = 101.5(1.26)
  - asa_5545-x_firmware = 9.9(2)
  - asa_5545-x_firmware = 101.5(1.26)
  - asa_5550_firmware = 9.9(2)
  - asa_5550_firmware = 101.5(1.26)
  - asa_5555-x_firmware = 9.9(2)
  - asa_5555-x_firmware = 101.5(1.26)
  - asa_5580_firmware = 9.9(2)
  - asa_5580_firmware = 101.5(1.26)
  - asa_5585-x_firmware = 9.9(2)
  - asa_5585-x_firmware = 101.5(1.26)
patched:
  - secure_firewall_threat_defense 6.4.0.6
published: '2020-05-06'
updated: '2026-08-11'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2020-3179'
references:
  - url: >-
      https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ftd-dos-2-sS2h7aWe
    label: psirt@cisco.com
  - url: >-
      https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ftd-dos-2-sS2h7aWe
    label: af854a3a-2127-422b-91ae-364da2661108
tags:
  - nvd
epss: 0.01984
epssPercentile: 0.79679
ingestedAt: '2026-08-11T19:48:27.379Z'
---

## Overview

A vulnerability in the generic routing encapsulation (GRE) tunnel decapsulation feature of Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. The vulnerability is due to a memory handling error when GRE over IPv6 traffic is processed. An attacker could exploit this vulnerability by sending crafted GRE over IPv6 packets with either IPv4 or IPv6 payload through an affected device. A successful exploit could allow the attacker to cause the device to crash, resulting in a DoS condition.

## Affected

- `secure_firewall_threat_defense >= 6.3.0, < 6.3.0.5`
- `secure_firewall_threat_defense >= 6.4.0, < 6.4.0.6`
- `asa_5505_firmware = 9.9(2)`
- `asa_5505_firmware = 101.5(1.26)`
- `asa_5510_firmware = 9.9(2)`
- `asa_5510_firmware = 101.5(1.26)`
- `asa_5512-x_firmware = 9.9(2)`
- `asa_5512-x_firmware = 101.5(1.26)`
- `asa_5515-x_firmware = 9.9(2)`
- `asa_5515-x_firmware = 101.5(1.26)`
- `asa_5520_firmware = 9.9(2)`
- `asa_5520_firmware = 101.5(1.26)`
- `asa_5525-x_firmware = 9.9(2)`
- `asa_5525-x_firmware = 101.5(1.26)`
- `asa_5540_firmware = 9.9(2)`
- `asa_5540_firmware = 101.5(1.26)`
- `asa_5545-x_firmware = 9.9(2)`
- `asa_5545-x_firmware = 101.5(1.26)`
- `asa_5550_firmware = 9.9(2)`
- `asa_5550_firmware = 101.5(1.26)`
- `asa_5555-x_firmware = 9.9(2)`
- `asa_5555-x_firmware = 101.5(1.26)`
- `asa_5580_firmware = 9.9(2)`
- `asa_5580_firmware = 101.5(1.26)`
- `asa_5585-x_firmware = 9.9(2)`
- `asa_5585-x_firmware = 101.5(1.26)`

## Remediation

Upgrade past the affected range:

- `secure_firewall_threat_defense 6.4.0.6`
