Denial of Service Vulnerability in Cisco ASA and FTD SSL VPN
CVE-2023-20042
7.5HIGH
Key Information:
- Vendor
- Cisco
- Vendor
- CVE Published:
- 1 November 2023
Summary
A flaw in the SSL VPN functionality of Cisco Adaptive Security Appliance and Cisco Firepower Threat Defense allows an unauthenticated remote attacker to craft specific SSL/TLS traffic that disrupts the session handling process. This exploitation could lead to a depletion of session handlers, resulting in a denial of service condition on the affected device, thus hindering the establishment of new sessions.
Affected Version(s)
Cisco Adaptive Security Appliance (ASA) Software 9.16.1
Cisco Adaptive Security Appliance (ASA) Software 9.16.1.28
Cisco Adaptive Security Appliance (ASA) Software 9.16.2
References
CVSS V3.1
Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved