SSL Traffic Decryption Vulnerability in Cisco Firepower Threat Defense Software
CVE-2017-12245
Key Information:
- Vendor
- Cisco
- Vendor
- CVE Published:
- 5 October 2017
Summary
A flaw in the SSL traffic decryption process of Cisco Firepower Threat Defense Software allows unauthenticated remote attackers to potentially cause memory depletion in affected devices. The vulnerability occurs when the Firepower Detection Snort Engine improperly manages the decryption of SSL traffic, leading to a steady consumption of system memory. Attackers can exploit this by transmitting malicious SSL traffic, which may diminish the device's performance and ultimately inhibit its ability to forward traffic, thus causing a denial of service condition. This issue impacts multiple Cisco security appliances running the specified software versions.
Affected Version(s)
Cisco Firepower Detection Engine Cisco Firepower Detection Engine
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved