QID 317382
QID 317382: Cisco Firepower Threat Defense (FTD) Software ICMPv6 with Snort 2 Denial of Service (DoS) Vulnerability (cisco-sa-ftd-icmpv6-dos-4eMkLuN)
A vulnerability in ICMPv6 inspection when configured with the Snort 2 detection engine for Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause the CPU of an affected device to spike to 100 percent, which could stop all traffic processing and result in a denial of service (DoS) condition. FTD management traffic is not affected by this vulnerability.
Note: To recover from the DoS condition, the Snort 2 Detection Engine or the Cisco FTD device may need to be restarted.
Affected Products
From 6.2.3 prior to 7.0.6
From 7.1.0 prior to 7.2.4
From 7.3.0 prior to 7.3.1.2
QID Detection Logic (Authenticated):
This QID will check the version retrieved via Unix Auth using "show version" command.
Note: This QID is not checking for Snort 2 status. Hence QID is kept as potential
A successful exploit could allow the attacker to cause the device to exhaust CPU resources and stop processing traffic, resulting in a DoS condition.
Customers are advised to refer to cisco-sa-ftd-icmpv6-dos-4eMkLuN for more information.
- cisco-sa-ftd-icmpv6-dos-4eMkLuN -
sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ftd-icmpv6-dos-4eMkLuN
CVEs related to QID 317382
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| cisco-sa-ftd-icmpv6-dos-4eMkLuN |
|