CVE-2020-3555Medium· 6.8▾ SunlitA vulnerability in the SIP inspection process of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause a crash and reload of an affecte…
▾ Sunlit zone — Low / medium · no exploitation signal
impact 37.4 · likelihood 0.3 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Aug 11.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
1.7%
A vulnerability in the SIP inspection process of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause a crash and reload of an affected device, resulting in a denial of service (DoS) condition. The vulnerability is due to a watchdog timeout and crash during the cleanup of threads that are associated with a SIP connection that is being deleted from the connection list. An attacker could exploit this vulnerability by sending a high rate of crafted SIP traffic through an affected device. A successful exploit could allow the attacker to cause a watchdog timeout and crash, resulting in a crash and reload of the affected device.
adaptive_security_appliance < 9.6.4.43secure_firewall_threat_defense <= 6.2.2secure_firewall_threat_defense >= 6.3.0, < 6.3.0.6secure_firewall_threat_defense >= 6.4.0, < 6.4.0.10secure_firewall_threat_defense >= 6.5.0, < 6.5.0.5secure_firewall_threat_defense = 6.6.0adaptive_security_appliance_software >= 9.7.0, < 9.8.4.24adaptive_security_appliance_software >= 9.9.0, < 9.9.2.80adaptive_security_appliance_software >= 9.10.0, < 9.10.1.43adaptive_security_appliance_software >= 9.12.0, < 9.12.4.2adaptive_security_appliance_software >= 9.13.0, < 9.13.1.13adaptive_security_appliance_software >= 9.14.0, < 9.14.1.19Upgrade past the affected range:
adaptive_security_appliance 9.6.4.43secure_firewall_threat_defense 6.5.0.5adaptive_security_appliance_software 9.14.1.19Connected by shared product, vendor, weakness, or advisory.
CVE-2020-3572High· 8.6A vulnerability in the SSL/TLS session handler of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condi…
CVE-2020-3564Medium· 5.3A vulnerability in the FTP inspection engine of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to bypass FTP inspection
CVE-2020-3561Medium· 4.7A vulnerability in the Clientless SSL VPN (WebVPN) of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to inject arbitrary HTTP headers in …
CVE-2020-3554High· 7.5A vulnerability in the TCP packet processing of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) conditi…
CVE-2020-3529High· 8.6A vulnerability in the SSL VPN negotiation process for Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause a reload of an affected de…
CVE-2020-3528High· 8.6A vulnerability in the OSPF Version 2 (OSPFv2) implementation of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause an affected devi…