CVE-2020-3196

Severity
8.6HIGH
EPSS
1.9%
top 16.96%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMay 6
Latest updateMay 24

Description

A vulnerability in the Secure Sockets Layer (SSL)/Transport Layer Security (TLS) handler of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to exhaust memory resources on the affected device, leading to a denial of service (DoS) condition. The vulnerability is due to improper resource management for inbound SSL/TLS connections. An attacker could exploit this vulnerability by establishing multiple S

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:HExploitability: 3.9 | Impact: 4.0

Affected Packages15 packages

NVDcisco/firepower_threat_defense6.2.36.2.3.16+3
NVDcisco/asa_5505_firmware100.13\(0\), 9.4\(4\), 9.8\(4.18\)+2
NVDcisco/asa_5510_firmware100.13\(0\), 9.4\(4\), 9.8\(4.18\)+2

🔴Vulnerability Details

2
GHSA
GHSA-57vc-vmwg-pg76: A vulnerability in the Secure Sockets Layer (SSL)/Transport Layer Security (TLS) handler of Cisco Adaptive Security Appliance (ASA) Software and Cisco2022-05-24
CVEList
Cisco Adaptive Security Appliance Software and Firepower Threat Defense Software SSL/TLS Denial of Service Vulnerability2020-05-06

📋Vendor Advisories

1
Cisco
Cisco Adaptive Security Appliance Software and Firepower Threat Defense Software SSL/TLS Denial of Service Vulnerability2020-05-06
CVE-2020-3196 (HIGH CVSS 8.6) | A vulnerability in the Secure Socke | cvebase.io