CVE-2020-3304High· 8.6▾ TwilightA vulnerability in the web interface of Cisco Adaptive Security Appliance (ASA) Software and Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause an affected device to reload unexpectedly, resu…
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 47.3 · likelihood 0.8 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Aug 11.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
3.9%
3.9% → 3.9%
A vulnerability in the web interface of Cisco Adaptive Security Appliance (ASA) Software and Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause an affected device to reload unexpectedly, resulting in a denial of service (DoS) condition. The vulnerability is due to a lack of proper input validation of HTTP requests. An attacker could exploit this vulnerability by sending a crafted HTTP request to an affected device. An exploit could allow the attacker to cause a DoS condition. Note: This vulnerability applies to IP Version 4 (IPv4) and IP Version 6 (IPv6) HTTP traffic.
adaptive_security_appliance < 9.6.4.45secure_firewall_threat_defense < 6.3.0.6secure_firewall_threat_defense >= 6.4.0, < 6.4.0.10secure_firewall_threat_defense >= 6.5.0, < 6.5.0.5secure_firewall_threat_defense >= 6.6.0, < 6.6.1adaptive_security_appliance_software >= 9.8.0, < 9.8.4.22adaptive_security_appliance_software >= 9.9.0, < 9.9.2.80adaptive_security_appliance_software >= 9.10.0, < 9.10.1.44adaptive_security_appliance_software >= 9.12.0, < 9.12.3.12adaptive_security_appliance_software >= 9.13.0, < 9.13.1.12adaptive_security_appliance_software >= 9.14.0, < 9.14.1.10Upgrade past the affected range:
adaptive_security_appliance 9.6.4.45secure_firewall_threat_defense 6.6.1adaptive_security_appliance_software 9.14.1.10Connected by shared product, vendor, weakness, or advisory.
CVE-2020-3554High· 7.5A vulnerability in the TCP packet processing of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) conditi…
CVE-2020-3529High· 8.6A vulnerability in the SSL VPN negotiation process for Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause a reload of an affected de…
CVE-2020-3528High· 8.6A vulnerability in the OSPF Version 2 (OSPFv2) implementation of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause an affected devi…
CVE-2020-3306High· 7.5A vulnerability in the DHCP module of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on the …
CVE-2020-3305High· 7.5A vulnerability in the implementation of the Border Gateway Protocol (BGP) module in Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to ca…
CVE-2020-3478High· 8.1A vulnerability in the REST API of Cisco Enterprise NFV Infrastructure Software (NFVIS) could allow an authenticated, remote attacker to overwrite certain files that should be restricted on an affected device