Denial of Service Vulnerability in Cisco ASA and FTD SSL VPN
CVE-2023-20042
7.5HIGH
Key Information:
- Vendor
Cisco
- Vendor
- CVE Published:
- 1 November 2023
What is CVE-2023-20042?
A flaw in the SSL VPN functionality of Cisco Adaptive Security Appliance and Cisco Firepower Threat Defense allows an unauthenticated remote attacker to craft specific SSL/TLS traffic that disrupts the session handling process. This exploitation could lead to a depletion of session handlers, resulting in a denial of service condition on the affected device, thus hindering the establishment of new sessions.
Affected Version(s)
Cisco Adaptive Security Appliance (ASA) Software 9.16.1
Cisco Adaptive Security Appliance (ASA) Software 9.16.1.28
Cisco Adaptive Security Appliance (ASA) Software 9.16.2