30
30
30
Cisco Secure Firewall Threat Defense Software Snort 2 SSL/TLS Denial of Service Vulnerability
Cisco fixed an SSL certificate parsing flaw in FTD's Snort 2 engine letting unauthenticated remote attackers force detection engine restarts.
Incomplete validation of SSL certificates in the Snort 2 Detection Engine of Cisco Secure Firewall Threat Defense software allows an unauthenticated, remote attacker to send a crafted SSL connection setup request for parsing. A successful exploit restarts the Snort 2 Detection Engine unexpectedly, causing a denial of service. Cisco has released software updates, and no workarounds address the vulnerability.
32
45
30
30
30
30
45
45
30
30
30
30
30
30
35
30
30
30
30
45
30
30
30
30
30
30
30
30
45
45
30
30
30
30
30
30
30