QID 317398

QID 317398: Cisco Firepower Threat Defense (FTD) Software Server Message Block (SMB) Protocol Snort 3 Detection Engine Bypass and Denial of Service (DoS) Vulnerability (cisco-sa-ftd-smbsnort3-dos-pfOjOYUV)

A vulnerability in the interaction between the Server Message Block (SMB) protocol preprocessor and the Snort 3 detection engine for Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to bypass the configured policies or cause a denial of service (DoS) condition on an affected device.

Note: This QID is not checking for Snort 3 status. Hence QID is kept as practice

Affected Products
From 7.1.0 prior to 7.2.4
From 7.2.0 prior to 7.2.0.1
From 7.3.0 prior to 7.3.1.2

QID Detection Logic (Authenticated):
This QID will check the version retrieved via Unix Auth using "show version" command.

A successful exploit could allow the attacker to cause the Snort process to reload, resulting in a DoS condition.

  • CVSS V3 rated as Medium - 5.8 severity.
  • CVSS V2 rated as Medium - 5 severity.
  • Solution

    Customers are advised to refer to cisco-sa-ftd-smbsnort3-dos-pfOjOYUV for more information.

    CVEs related to QID 317398

    Software Advisories
    Advisory ID Software Component Link
    cisco-sa-ftd-smbsnort3-dos-pfOjOYUV URL Logo sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ftd-smbsnort3-dos-pfOjOYUV