QID 317170

Date Published: 2022-05-05

QID 317170: Cisco Firepower Threat Defense (FTD) Software Transmission Control Protocol (TCP) Proxy Denial of Service (DoS) Vulnerability (cisco-sa-ftd-tcp-dos-kM9SHhOu)

A vulnerability in the TCP proxy functionality of Cisco Firepower Threat Defense (FTD) Software
could allow an unauthenticated, remote attacker to trigger a denial of service (DoS) condition.

Affected Products
Cisco products if they are running Cisco FTD Software Release 7.0.0 or Release 7.0.0.1 and have the TCP Intercept feature enabled.
Note: Potential Detection as cannot confirm TCP Intercept feature enabled.

QID Detection Logic (Authenticated):
The check matches Cisco FTD OS version retrieved via Unix Auth using "version" command.

A successful exploit could allow the attacker to cause the device to reload, resulting in a DoS condition.

  • CVSS V3 rated as High - 7.5 severity.
  • CVSS V2 rated as High - 7.1 severity.
  • Solution

    Customers are advised to refer to cisco-sa-ftd-tcp-dos-kM9SHhOu for more information.

    CVEs related to QID 317170

    Software Advisories
    Advisory ID Software Component Link
    cisco-sa-ftd-tcp-dos-kM9SHhOu URL Logo tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ftd-tcp-dos-kM9SHhOu