CVE-2020-27124

CWE-4574 documents4 sources
Severity
8.6HIGH
EPSS
1.8%
top 17.35%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedNov 18

Description

A vulnerability in the SSL/TLS handler of Cisco Adaptive Security Appliance (ASA) Software could allow an unauthenticated, remote attacker to cause the affected device to reload unexpectedly, leading to a denial of service (DoS) condition. The vulnerability is due to improper error handling on established SSL/TLS connections. An attacker could exploit this vulnerability by establishing an SSL/TLS connection with the affected device and then sending a malicious SSL/TLS message within that connect

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:HExploitability: 3.9 | Impact: 4.0

Affected Packages2 packages

🔴Vulnerability Details

2
CVEList
Cisco Adaptive Security Appliance Software SSL/TLS Denial of Service Vulnerability2024-11-18
GHSA
GHSA-j69q-qfwm-m736: A vulnerability in the SSL/TLS handler of Cisco Adaptive Security Appliance (ASA) Software could allow an unauthenticated, remote attacker to cause th2024-11-18

📋Vendor Advisories

1
Cisco
Cisco Adaptive Security Appliance Software SSL/TLS Denial of Service Vulnerability2020-10-22
CVE-2020-27124 (HIGH CVSS 8.6) | A vulnerability in the SSL/TLS hand | cvebase.io