SSL Traffic Decryption Vulnerability in Cisco Firepower Threat Defense Software
CVE-2017-12245
8.6HIGH
Key Information:
- Vendor
Cisco
- Vendor
- CVE Published:
- 5 October 2017
What is CVE-2017-12245?
A flaw in the SSL traffic decryption process of Cisco Firepower Threat Defense Software allows unauthenticated remote attackers to potentially cause memory depletion in affected devices. The vulnerability occurs when the Firepower Detection Snort Engine improperly manages the decryption of SSL traffic, leading to a steady consumption of system memory. Attackers can exploit this by transmitting malicious SSL traffic, which may diminish the device's performance and ultimately inhibit its ability to forward traffic, thus causing a denial of service condition. This issue impacts multiple Cisco security appliances running the specified software versions.
Affected Version(s)
Cisco Firepower Detection Engine Cisco Firepower Detection Engine