CVE-2023-20006
Summary
| CVE | CVE-2023-20006 |
|---|---|
| State | PUBLISHED |
| Assigner | cisco |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2023-06-28 15:15:09 UTC |
| Updated | 2026-08-11 19:33:44 UTC |
| Description | A vulnerability in the hardware-based SSL/TLS cryptography functionality of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software for Cisco Firepower 2100 Series Appliances could allow an unauthenticated, remote attacker to cause an affected device to reload unexpectedly, resulting in a denial of service (DoS) condition. This vulnerability is due to an implementation error within the cryptographic functions for SSL/TLS traffic processing when they are offloaded to the hardware. An attacker could exploit this vulnerability by sending a crafted stream of SSL/TLS traffic to an affected device. A successful exploit could allow the attacker to cause an unexpected error in the hardware-based cryptography engine, which could cause the device to reload. |
Risk And Classification
Primary CVSS: v3.1 7.5 HIGH from [email protected]
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
EPSS: 0.009190000 probability, percentile 0.570550000 (date 2026-08-12)
Problem Types: CWE-681 | CWE-681 Incorrect Conversion between Numeric Types
| Version | Source | Type | Score | Severity | Vector |
|---|---|---|---|---|---|
| 3.1 | [email protected] | Primary | 7.5 | HIGH | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |
| 3.1 | [email protected] | Secondary | 8.6 | HIGH | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H |
| 3.1 | CNA | CVSSV3_1 | 8.6 | HIGH | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H |
CVSS v3.1 Breakdown
Attack Vector
NetworkAttack Complexity
LowPrivileges Required
NoneUser Interaction
NoneScope
UnchangedConfidentiality
NoneIntegrity
NoneAvailability
HighCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Operating System | Cisco | Adaptive Security Appliance Software | 9.16.4 | All | All | All |
| Operating System | Cisco | Adaptive Security Appliance Software | 9.18.2 | All | All | All |
| Operating System | Cisco | Adaptive Security Appliance Software | 9.18.2.5 | All | All | All |
| Hardware | Cisco | Firepower 2110 | - | All | All | All |
| Hardware | Cisco | Firepower 2120 | - | All | All | All |
| Hardware | Cisco | Firepower 2130 | - | All | All | All |
| Hardware | Cisco | Firepower 2140 | - | All | All | All |
| Application | Cisco | Secure Firewall Threat Defense | 7.2.1 | All | All | All |
| Application | Cisco | Secure Firewall Threat Defense | 7.2.2 | All | All | All |
| Application | Cisco | Secure Firewall Threat Defense | 7.2.3 | All | All | All |
Vendor Declared Affected Products
| Source | Vendor | Product | Version | Platforms |
|---|---|---|---|---|
| CNA | Cisco | Cisco Adaptive Security Appliance ASA Software | affected 9.16.4 | Not specified |
| CNA | Cisco | Cisco Adaptive Security Appliance ASA Software | affected 9.18.2 | Not specified |
| CNA | Cisco | Cisco Adaptive Security Appliance ASA Software | affected 9.18.2.5 | Not specified |
| CNA | Cisco | Cisco Firepower Threat Defense Software | affected 7.2.1 | Not specified |
| CNA | Cisco | Cisco Firepower Threat Defense Software | affected 7.2.2 | Not specified |
| CNA | Cisco | Cisco Firepower Threat Defense Software | affected 7.2.3 | Not specified |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Cisco Adaptive Security Appliance Software and Firepower Threat Defense Software for Firepower 2100 Series Appliances SSL/TLS Denial of Service Vulnerability | af854a3a-2127-422b-91ae-364da2661108 | sec.cloudapps.cisco.com | Vendor Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
Additional Advisory Data
Exploits
CNA: The Cisco Product Security Incident Response Team (PSIRT) is not aware of any public announcements or malicious use of the vulnerability that is described in this advisory.
Legacy QID Mappings
- 317334 Cisco Adaptive Security Appliance Software Denial of Service (DoS) Vulnerability (cisco-sa-asaftd-ssl-dos-uu7mV5p6)