Cisco Secure Firewall Adaptive Security Appliance and Secure Firewall Threat Defense Software TCP DNS Denial of Service Vulnerability
Cisco disclosed a TCP DNS flaw in ASA and FTD firewall software letting unauthenticated remote attackers trigger device reloads and denial of service.
A logic error in the DNS over TCP implementation of Cisco Secure Firewall ASA and FTD software mishandles buffer-size tracking when parsing DNS queries. An unauthenticated, remote attacker can send a crafted reply to a DNS query sent from the targeted device, causing the TCP DNS response handler to restart and the device to reload. The result is a denial of service condition on affected firewalls.