Denial of Service Vulnerability in Cisco Firepower System Software
CVE-2017-3885
5.9MEDIUM
What is CVE-2017-3885?
A vulnerability exists in the detection engine reassembly of SSL packets in Cisco Firepower System Software. This flaw can be exploited by an unauthenticated remote attacker to trigger a denial of service condition. When the device's SSL policy includes a rule for traffic decryption, the Snort process may consume excessive CPU resources, leading to significant performance degradation. The issue is relevant for specific software releases, making it crucial for users to assess their configurations and implement necessary updates.
Affected Version(s)
Cisco Firepower Detection Engine Cisco Firepower Detection Engine