QID 317268
Date Published: 2022-11-14
QID 317268: Cisco Firepower Threat Defense (FTD) Software Generic Routing Encapsulation Denial of Service (DoS) Vulnerability (cisco-sa-ftd-gre-dos-hmedHQPM)
A vulnerability in the generic routing encapsulation (GRE) tunnel decapsulation feature of Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device.
Affected Products
TThis vulnerability affects Cisco FTD Software releases 6.3.0 and later.
Note: GRE tunnel decapsulation in the LINA engine was introduced in Cisco FTD Software Release 6.3.0. This feature is enabled by default and cannot be disabled.
A successful exploit could allow the attacker to cause the device to restart, resulting in a DoS condition.
Customers are advised to refer to cisco-sa-ftd-gre-dos-hmedHQPM for more information.Workaround:
administrators may choose to bypass decapsulation for GRE-tunneled flows by following these steps from the Cisco FMC GUI:
Click Policies and choose Prefilter under Access Control.
Click Edit under the Prefilter Policy that is associated with the access policy assigned to the device.
Change the GRE tunnel rule type action to Fastpath.
Click Save.
Click Deploy.
Note: This configuration will bypass the detection engine for GRE-tunneled traffic.
- cisco-sa-ftd-gre-dos-hmedHQPM#fs -
tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ftd-gre-dos-hmedHQPM#fs
CVEs related to QID 317268
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| cisco-sa-ftd-gre-dos-hmedHQPM |
|