Cisco Secure Firewall Threat Defense Software TLS 1.3 Denial of Service Vulnerability
A TLS 1.3 buffer management flaw in Cisco Secure Firewall Threat Defense lets remote attackers crash the LINA process and reload devices.
A vulnerability in the TLS 1.3 implementation of Cisco Secure Firewall Threat Defense (FTD) software allows an unauthenticated remote attacker to cause a denial of service via crafted TLS 1.3 packets sent to a TLS 1.3-enabled listening socket. Improper buffer management causes the LINA process to crash, forcing a device reload that can occur before or after connection authentication. Cisco has released software updates to address the flaw.