QID 317392
QID 317392: Cisco Firepower Threat Defense (FTD) Software SSL/Transport Layer Security (TLS) Uniform Resource Locator (URL) Category and Snort 3 Detection Engine Bypass and Denial of Service (DoS) Vulnerability (cisco-sa-sa-ftd-snort3-urldos-OccFQTeX)
A vulnerability in the SSL file policy implementation of Cisco Firepower Threat Defense (FTD) Software that occurs when the SSL/TLS connection is configured with a URL Category and the Snort 3 detection engine could allow an unauthenticated, remote attacker to cause the Snort 3 detection engine to unexpectedly restart.
Affected Products
From 7.1.0 prior to 7.2.4
From 7.3.0 prior to 7.3.1.2
QID Detection Logic (Authenticated):
This QID will check the version retrieved via Unix Auth using "show version" command.
Note: This QID is not checking for Snort 3 status. Hence QID is kept as potential
A successful exploit could allow the attacker to trigger an unexpected reload of the Snort 3 detection engine, resulting in either a bypass or denial of service (DoS) condition
Customers are advised to refer to cisco-sa-sa-ftd-snort3-urldos-OccFQTeX for more information.
- cisco-sa-sa-ftd-snort3-urldos-OccFQTeX -
sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sa-ftd-snort3-urldos-OccFQTeX
CVEs related to QID 317392
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| cisco-sa-sa-ftd-snort3-urldos-OccFQTeX |
|