CVE-2017-3887
published 2017-04-07CVE-2017-3887: A vulnerability in the detection engine that handles Secure Sockets Layer (SSL) packets for Cisco Firepower System Software could allow an unauthenticated…
PriorityP429medium5.9CVSS 3.0
AVNACHPRNUINSUCNINAH
EPSS
1.27%
66.7th percentile
A vulnerability in the detection engine that handles Secure Sockets Layer (SSL) packets for Cisco Firepower System Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition because the Snort process unexpectedly restarts. This vulnerability affects Cisco Firepower System Software prior to the first fixed release when it is configured with an SSL Decrypt-Resign policy. More Information: CSCvb62292. Known Affected Releases: 6.0.1 6.1.0 6.2.0. Known Fixed Releases: 6.2.0 6.1.0.2.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | firepower_detection_engine_ssl | — | — |
| cisco | firepower_threat_defense | — | — |
| cisco | firepower_threat_defense | — | — |
| cisco | firepower_threat_defense | — | — |
CVSS provenance
nvdv3.05.9MEDIUMCVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:N/A:P
vendor_cisco6.8MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Cisco
Cisco Firepower Detection Engine SSL Denial of Service Vulnerability
vendor_cisco·2017-04-05·CVSS 6.8
CVE-2017-3887 [MEDIUM] CWE-119 Cisco Firepower Detection Engine SSL Denial of Service Vulnerability
Cisco Firepower Detection Engine SSL Denial of Service Vulnerability
A vulnerability in the detection engine that handles Secure Sockets Layer (SSL) packets for Cisco Firepower System Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition because the Snort process unexpectedly restarts.
The vulnerability is due to improper error handling of an SSL packet in an established SSL connection. An attacker could exploit this vulnerability by sending a crafted SSL packet stream to the detection engine on the targeted device. An exploit could allow the attacker to cause a DoS condition if the Snort process restarts, causing traffic inspection to be bypassed or traffic to be dropped.
There are no workarounds that address this vulnerability.
This adv
Cisco
Cisco Firepower Detection Engine SSL Denial of Service Vulnerability
vendor_cisco·CVSS 3.0
CVE-2017-3887 Cisco Firepower Detection Engine SSL Denial of Service Vulnerability
CVE-2017-3887: Cisco Firepower Detection Engine SSL Denial of Service Vulnerability
A vulnerability in the detection engine that handles Secure Sockets Layer (SSL) packets for Cisco Firepower System Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition because the Snort process unexpectedly restarts. The vulnerability is due to improper error handling of an SSL packet in an established SSL connection. An attacker could exploit this vulnerability by sending a crafted SSL packet stream to the detection engine on the targeted device. An exploit could allow the attacker to cause a DoS condition if the Snort process restarts, causing traffic inspection to be bypassed or traffic to be dropped. There are no
CVSS: 3.0
CWE: CWE-119, CWE-119
Bug IDs: C
GHSA
GHSA-6h9g-8whp-24px: A vulnerability in the detection engine that handles Secure Sockets Layer (SSL) packets for Cisco Firepower System Software could allow an unauthentic
ghsa_unreviewed·2022-05-13
CVE-2017-3887 [MEDIUM] CWE-755 GHSA-6h9g-8whp-24px: A vulnerability in the detection engine that handles Secure Sockets Layer (SSL) packets for Cisco Firepower System Software could allow an unauthentic
A vulnerability in the detection engine that handles Secure Sockets Layer (SSL) packets for Cisco Firepower System Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition because the Snort process unexpectedly restarts. This vulnerability affects Cisco Firepower System Software prior to the first fixed release when it is configured with an SSL Decrypt-Resign policy. More Information: CSCvb62292. Known Affected Releases: 6.0.1 6.1.0 6.2.0. Known Fixed Releases: 6.2.0 6.1.0.2.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2017-04-07
Published