QID 316961
Date Published: 2021-04-30
QID 316961: Cisco Firepower Threat Defense Software SIP Denial of Service Vulnerability(cisco-sa-asa-ftd-sipdos-GGwmMerC)
A vulnerability in the SIP inspection engine of Cisco Firepower Threat Defense (FTD) Software
could allow an unauthenticated, remote attacker to cause a crash and reload of an affected device,
resulting in a denial of service (DoS) condition.
Affected Products
Cisco products if they are running a vulnerable release of Cisco ASA Software or FTD Software and have SIP inspection configured.
From 6.2.2 Prior to 6.4.0.12(May 2021)
From 6.5.0 Prior to 6.6.4
From 6.7.0 Prior to 6.7.0.2
Note: SIP inspection is enabled by default on Cisco Firepower Threat Defense (FTD) Software.
QID Detection Logic (Authenticated):
The check matches Cisco Firepower Threat Defense (FTD) Software version retrieved via Unix Auth using "show version" command.
A successful exploit could allow the attacker to cause a crash and reload of the affected device.
Customers are advised to refer to cisco-sa-asa-ftd-sipdos-GGwmMerC for more information.Workaround:
There are no workarounds that address this vulnerability. However, there are mitigation options that apply to both physical and virtual appliances.
i. Disable SIP Inspection
ii. Allow Only Trusted SIP Hosts Using ACLs
- cisco-sa-asa-ftd-sipdos-GGwmMerC -
tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-asa-ftd-sipdos-GGwmMerC
CVEs related to QID 316961
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| cisco-sa-asa-ftd-sipdos-GGwmMerC |
|