Cisco Firepower 1000 Series SSL/TLS Denial of Service Vulnerability
Summary
| CVE | CVE-2020-3283 |
|---|---|
| State | PUBLISHED |
| Assigner | cisco |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2020-05-06 17:15:12 UTC |
| Updated | 2026-08-11 19:33:44 UTC |
| Description | A vulnerability in the Secure Sockets Layer (SSL)/Transport Layer Security (TLS) handler of Cisco Firepower Threat Defense (FTD) Software when running on the Cisco Firepower 1000 Series platform could allow an unauthenticated, remote attacker to trigger a denial of service (DoS) condition on an affected device. The vulnerability is due to a communication error between internal functions. An attacker could exploit this vulnerability by sending a crafted SSL/TLS message to an affected device. A successful exploit could allow the attacker to cause a buffer underrun, which leads to a crash. The crash causes the affected device to reload. |
Risk And Classification
Primary CVSS: v3.1 8.6 HIGH from [email protected]
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H
EPSS: 0.019560000 probability, percentile 0.784540000 (date 2026-08-12)
Problem Types: CWE-119 | CWE-787 | CWE-119 CWE-119
| Version | Source | Type | Score | Severity | Vector |
|---|---|---|---|---|---|
| 3.1 | [email protected] | Primary | 8.6 | HIGH | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H |
| 3.0 | [email protected] | Secondary | 8.6 | HIGH | CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H |
| 3.0 | CNA | DECLARED | 8.6 | HIGH | CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H |
| 2.0 | [email protected] | Primary | 5 | AV:N/AC:L/Au:N/C:N/I:N/A:P |
CVSS v3.1 Breakdown
Attack Vector
NetworkAttack Complexity
LowPrivileges Required
NoneUser Interaction
NoneScope
ChangedConfidentiality
NoneIntegrity
NoneAvailability
HighCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H
CVSS v3.0 Breakdown
Attack Vector
NetworkAttack Complexity
LowPrivileges Required
NoneUser Interaction
NoneScope
ChangedConfidentiality
NoneIntegrity
NoneAvailability
HighCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
LowAuthentication
NoneConfidentiality
NoneIntegrity
NoneAvailability
PartialAV:N/AC:L/Au:N/C:N/I:N/A:P
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Hardware | Cisco | Asa 5505 | - | All | All | All |
| Operating System | Cisco | Asa 5505 Firmware | 9.12\(2.12\) | All | All | All |
| Operating System | Cisco | Asa 5505 Firmware | 9.13\(0.33\) | All | All | All |
| Hardware | Cisco | Asa 5510 | - | All | All | All |
| Operating System | Cisco | Asa 5510 Firmware | 9.12\(2.12\) | All | All | All |
| Operating System | Cisco | Asa 5510 Firmware | 9.13\(0.33\) | All | All | All |
| Hardware | Cisco | Asa 5512-x | - | All | All | All |
| Operating System | Cisco | Asa 5512-x Firmware | 9.12\(2.12\) | All | All | All |
| Operating System | Cisco | Asa 5512-x Firmware | 9.13\(0.33\) | All | All | All |
| Hardware | Cisco | Asa 5515-x | - | All | All | All |
| Operating System | Cisco | Asa 5515-x Firmware | 9.12\(2.12\) | All | All | All |
| Operating System | Cisco | Asa 5515-x Firmware | 9.13\(0.33\) | All | All | All |
| Hardware | Cisco | Asa 5520 | - | All | All | All |
| Operating System | Cisco | Asa 5520 Firmware | 9.12\(2.12\) | All | All | All |
| Operating System | Cisco | Asa 5520 Firmware | 9.13\(0.33\) | All | All | All |
| Hardware | Cisco | Asa 5525-x | - | All | All | All |
| Operating System | Cisco | Asa 5525-x Firmware | 9.12\(2.12\) | All | All | All |
| Operating System | Cisco | Asa 5525-x Firmware | 9.13\(0.33\) | All | All | All |
| Hardware | Cisco | Asa 5540 | - | All | All | All |
| Operating System | Cisco | Asa 5540 Firmware | 9.12\(2.12\) | All | All | All |
| Operating System | Cisco | Asa 5540 Firmware | 9.13\(0.33\) | All | All | All |
| Hardware | Cisco | Asa 5545-x | - | All | All | All |
| Operating System | Cisco | Asa 5545-x Firmware | 9.12\(2.12\) | All | All | All |
| Operating System | Cisco | Asa 5545-x Firmware | 9.13\(0.33\) | All | All | All |
| Hardware | Cisco | Asa 5550 | - | All | All | All |
| Operating System | Cisco | Asa 5550 Firmware | 9.12\(2.12\) | All | All | All |
| Operating System | Cisco | Asa 5550 Firmware | 9.13\(0.33\) | All | All | All |
| Hardware | Cisco | Asa 5555-x | - | All | All | All |
| Operating System | Cisco | Asa 5555-x Firmware | 9.12\(2.12\) | All | All | All |
| Operating System | Cisco | Asa 5555-x Firmware | 9.13\(0.33\) | All | All | All |
| Hardware | Cisco | Asa 5580 | - | All | All | All |
| Operating System | Cisco | Asa 5580 Firmware | 9.12\(2.12\) | All | All | All |
| Operating System | Cisco | Asa 5580 Firmware | 9.13\(0.33\) | All | All | All |
| Hardware | Cisco | Asa 5585-x | - | All | All | All |
| Operating System | Cisco | Asa 5585-x Firmware | 9.12\(2.12\) | All | All | All |
| Operating System | Cisco | Asa 5585-x Firmware | 9.13\(0.33\) | All | All | All |
| Hardware | Cisco | Firepower 1010 | - | All | All | All |
| Hardware | Cisco | Firepower 1020 | - | All | All | All |
| Hardware | Cisco | Firepower 1030 | - | All | All | All |
| Hardware | Cisco | Firepower 1040 | - | All | All | All |
| Application | Cisco | Secure Firewall Threat Defense | All | All | All | All |
Vendor Declared Affected Products
| Source | Vendor | Product | Version | Platforms |
|---|---|---|---|---|
| CNA | Cisco | Cisco Firepower Threat Defense Software | affected n/a | Not specified |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Cisco Firepower 1000 Series SSL/TLS Denial of Service Vulnerability | af854a3a-2127-422b-91ae-364da2661108 | tools.cisco.com | Vendor Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
Additional Advisory Data
Exploits
CNA: The Cisco Product Security Incident Response Team (PSIRT) is not aware of any public announcements or malicious use of the vulnerability that is described in this advisory.
There are currently no legacy QID mappings associated with this CVE.