A vulnerability in the Internet Key Exchange version 1 (IKEv1) feature of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition. The vulnerability is due to improper management of system memory. An attacker could exploit this vulnerability by sending malicious IKEv1 traffic to an affected device. A successful exploit could allow the attacker to cause a DoS condition on the affected device.
References
Link | Resource |
---|---|
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-asa-dos-BqYFRJt9 | Vendor Advisory |
Configurations
Configuration 1 (hide)
AND |
|
Configuration 2 (hide)
|
Information
Published : 2020-05-06 10:15
Updated : 2020-05-12 10:21
NVD link : CVE-2020-3303
Mitre link : CVE-2020-3303
JSON object : View
CWE
CWE-400
Uncontrolled Resource Consumption
Products Affected
cisco
- asa_5510
- asa_5550
- asa_5580
- asa_5520
- adaptive_security_appliance
- firepower_threat_defense
- asa_5505
- asa_5525-x
- asa_5515-x
- asa_5512-x
- asa_5585-x
- asa_5555-x