ZeroHour
Cisco Security Advisoriespublished ()ingested
Part of a story covered by 9 sources: “Cisco Patches Nine Secure Firewall ASA/FTD Vulnerabilities, Including ACL Bypass and Eight Denial-of-Service Flaws” — merged summary and timeline →

Cisco Secure Firewall Threat Defense Software Snort 2 SSL/TLS Denial of Service Vulnerability

mediumAdvisoryimportance 32
AI summary · glm-5.3-flash

Cisco fixed an SSL certificate parsing flaw in FTD's Snort 2 engine letting unauthenticated remote attackers force detection engine restarts.

Incomplete validation of SSL certificates in the Snort 2 Detection Engine of Cisco Secure Firewall Threat Defense software allows an unauthenticated, remote attacker to send a crafted SSL connection setup request for parsing. A successful exploit restarts the Snort 2 Detection Engine unexpectedly, causing a denial of service. Cisco has released software updates, and no workarounds address the vulnerability.

  • Incomplete SSL certificate validation affects the Snort 2 Detection Engine
  • Crafted SSL connection setup request triggers detection engine restart
  • Causes denial of service on Cisco FTD deployments
  • Software updates released; no workarounds available
Full article

A vulnerability in SSL/TLS certificate parsing in the Snort 2 Detection Engine of Cisco Secure Firewall Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause the Snort 2 Detection Engine to restart. This vulnerability is due to incomplete validation of the SSL certificate. An attacker could exploit this vulnerability by sending a crafted SSL connection setup request to be parsed by Snort 2. A successful exploit could allow the attacker to cause the Snort 2 Detection Engine to restart unexpectedly, resulting in a denial of service (DoS) condition. Cisco has released software updates that address this vulnerability. There are no workarounds that address this…

This source does not provide full text. Read it at sec.cloudapps.cisco.com.