QID 317398
QID 317398: Cisco Firepower Threat Defense (FTD) Software Server Message Block (SMB) Protocol Snort 3 Detection Engine Bypass and Denial of Service (DoS) Vulnerability (cisco-sa-ftd-smbsnort3-dos-pfOjOYUV)
A vulnerability in the interaction between the Server Message Block (SMB) protocol preprocessor and the Snort 3 detection engine for Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to bypass the configured policies or cause a denial of service (DoS) condition on an affected device.
Note: This QID is not checking for Snort 3 status. Hence QID is kept as practice
Affected Products
From 7.1.0 prior to 7.2.4
From 7.2.0 prior to 7.2.0.1
From 7.3.0 prior to 7.3.1.2
QID Detection Logic (Authenticated):
This QID will check the version retrieved via Unix Auth using "show version" command.
A successful exploit could allow the attacker to cause the Snort process to reload, resulting in a DoS condition.
Customers are advised to refer to cisco-sa-ftd-smbsnort3-dos-pfOjOYUV for more information.
- cisco-sa-ftd-smbsnort3-dos-pfOjOYUV -
sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ftd-smbsnort3-dos-pfOjOYUV
CVEs related to QID 317398
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| cisco-sa-ftd-smbsnort3-dos-pfOjOYUV |
|