Cisco Secure Firewall Adaptive Security Appliance and Secure Firewall Threat Defense Software Logging Denial of Service Vulnerability
Cisco patched an ASA/FTD rate-limiting flaw where TCP SYN floods trigger excessive syslog 419002 messages, causing high CPU and degraded performance.
A vulnerability in the system rate-limiting process for syslog message 419002 in Cisco Secure Firewall ASA and FTD Software allows an unauthenticated, remote attacker to cause high CPU utilization. The flaw results from improper rate limiting; an attacker can exploit it by sending a flood of TCP SYN packets, degrading device performance. Cisco has released software updates.
- Improper rate limiting of syslog message 419002 exhausts CPU
- Remote unauthenticated attacker floods TCP SYN packets to degrade performance
- Denial of service manifests as performance degradation rather than reload
- Cisco has released software updates
A vulnerability in the system rate-limiting process for syslog message 419002 of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause high CPU utilization on an affected device, resulting in a denial of service (DoS) condition. This vulnerability is due to improper rate limiting for syslog message 419002. An attacker could exploit this vulnerability by sending a flood of TCP synchronization (SYN) packets to an affected device. A successful exploit could allow the attacker to cause high CPU utilization, resulting in performance degradation. Cisco has released software…
This source does not provide full text. Read it at sec.cloudapps.cisco.com.