Denial of Service Vulnerability in Cisco ASA and FTD SSL VPN
CVE-2023-20042
Key Information:
- Vendor
Cisco
- Vendor
- CVE Published:
- 1 November 2023
What is CVE-2023-20042?
A flaw in the SSL VPN functionality of Cisco Adaptive Security Appliance and Cisco Firepower Threat Defense allows an unauthenticated remote attacker to craft specific SSL/TLS traffic that disrupts the session handling process. This exploitation could lead to a depletion of session handlers, resulting in a denial of service condition on the affected device, thus hindering the establishment of new sessions.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Cisco Adaptive Security Appliance (ASA) Software 9.16.1
Cisco Adaptive Security Appliance (ASA) Software 9.16.1.28
Cisco Adaptive Security Appliance (ASA) Software 9.16.2
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved