Denial of Service Vulnerability in Cisco Firepower System Software
CVE-2017-3885

5.9MEDIUM

Key Information:

Vendor
Cisco
Vendor
CVE Published:
7 April 2017

Summary

A vulnerability exists in the detection engine reassembly of SSL packets in Cisco Firepower System Software. This flaw can be exploited by an unauthenticated remote attacker to trigger a denial of service condition. When the device's SSL policy includes a rule for traffic decryption, the Snort process may consume excessive CPU resources, leading to significant performance degradation. The issue is relevant for specific software releases, making it crucial for users to assess their configurations and implement necessary updates.

Affected Version(s)

Cisco Firepower Detection Engine Cisco Firepower Detection Engine

References

CVSS V3.1

Score:
5.9
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.