QID 317395
QID 317395: Cisco Firepower Threat Defense (FTD) Software Secure Sockets Layer (SSL) and Snort 3 Detection Engine Bypass and Denial of Service (DoS) Vulnerability (cisco-sa-ftd-snort3-8U4HHxH8)
A vulnerability in the SSL/TLS certificate handling of Snort 3 Detection Engine integration with Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause the Snort 3 detection engine to restart.
Affected Products
Vulnerable versions are referred from the BugID CSCwb69096
This vulnerability affects Cisco products if they are running a vulnerable release of Cisco FTD Software configured with snort version 3
Note: This QID is not checking for Snort 3 status. Hence QID is kept as practice
Affected Products
From 6.7.0 prior to 7.0.6
From 7.2.0 prior to 7.2.1
QID Detection Logic (Authenticated):
This QID will check the version retrieved via Unix Auth using "show version" command.
A successful exploit could allow the attacker to cause the Snort 3 detection engine to reload, resulting in either a bypass or a denial of service (DoS) condition
Customers are advised to refer to cisco-sa-ftd-snort3-8U4HHxH8 for more information.
- cisco-sa-ftd-snort3-8U4HHxH8 -
sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ftd-snort3-8U4HHxH8
CVEs related to QID 317395
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| cisco-sa-ftd-snort3-8U4HHxH8 |
|