CVE-2020-3254
published 2020-05-06CVE-2020-3254: Multiple vulnerabilities in the Media Gateway Control Protocol (MGCP) inspection feature of Cisco Adaptive Security Appliance (ASA) Software and Firepower…
PriorityP343high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
1.92%
77.6th percentile
Multiple vulnerabilities in the Media Gateway Control Protocol (MGCP) inspection feature of Cisco Adaptive Security Appliance (ASA) Software and Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. The vulnerabilities are due to inefficient memory management. An attacker could exploit these vulnerabilities by sending crafted MGCP packets through an affected device. An exploit could allow the attacker to cause memory exhaustion resulting in a restart of an affected device, causing a DoS condition for traffic traversing the device.
Affected
22 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | adaptive_security_appliance | — | — |
| cisco | adaptive_security_appliance_software | >= 9.10 < 9.10.1.27 | 9.10.1.27 |
| cisco | adaptive_security_appliance_software | >= 9.12 < 9.12.2.1 | 9.12.2.1 |
| cisco | adaptive_security_appliance_software | >= 9.6 < 9.6.4.34 | 9.6.4.34 |
| cisco | adaptive_security_appliance_software | >= 9.8 < 9.8.4.7 | 9.8.4.7 |
| cisco | adaptive_security_appliance_software | >= 9.9 < 9.9.2.66 | 9.9.2.66 |
| cisco | asa_5505_firmware | — | — |
| cisco | asa_5510_firmware | — | — |
| cisco | asa_5512-x_firmware | — | — |
| cisco | asa_5515-x_firmware | — | — |
| cisco | asa_5520_firmware | — | — |
| cisco | asa_5525-x_firmware | — | — |
| cisco | asa_5540_firmware | — | — |
| cisco | asa_5545-x_firmware | — | — |
| cisco | asa_5550_firmware | — | — |
| cisco | asa_5555-x_firmware | — | — |
| cisco | asa_5580_firmware | — | — |
| cisco | asa_5585-x_firmware | — | — |
| cisco | cisco_adaptive_security_appliance_software | — | — |
| cisco | firepower_threat_defense | >= 6.2.3 < 6.2.3.16 | 6.2.3.16 |
| cisco | firepower_threat_defense | >= 6.3.0 < 6.3.0.6 | 6.3.0.6 |
| cisco | firepower_threat_defense | >= 6.4.0 < 6.4.0.4 | 6.4.0.4 |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
nvdv3.08.6HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H
nvdv2.07.8HIGHAV:N/AC:L/Au:N/C:N/I:N/A:C
vendor_cisco8.6HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-7r27-75hm-vvch: Multiple vulnerabilities in the Media Gateway Control Protocol (MGCP) inspection feature of Cisco Adaptive Security Appliance (ASA) Software and Firep
ghsa_unreviewed·2022-05-24
CVE-2020-3254 [HIGH] CWE-400 GHSA-7r27-75hm-vvch: Multiple vulnerabilities in the Media Gateway Control Protocol (MGCP) inspection feature of Cisco Adaptive Security Appliance (ASA) Software and Firep
Multiple vulnerabilities in the Media Gateway Control Protocol (MGCP) inspection feature of Cisco Adaptive Security Appliance (ASA) Software and Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. The vulnerabilities are due to inefficient memory management. An attacker could exploit these vulnerabilities by sending crafted MGCP packets through an affected device. An exploit could allow the attacker to cause memory exhaustion resulting in a restart of an affected device, causing a DoS condition for traffic traversing the device.
Cisco
Cisco Adaptive Security Appliance Software and Firepower Threat Defense Software Media Gateway Control Protocol Denial of Service Vulnerabilities
vendor_cisco·2020-05-06·CVSS 8.6
CVE-2020-3254 [HIGH] CWE-400 Cisco Adaptive Security Appliance Software and Firepower Threat Defense Software Media Gateway Control Protocol Denial of Service Vulnerabilities
Cisco Adaptive Security Appliance Software and Firepower Threat Defense Software Media Gateway Control Protocol Denial of Service Vulnerabilities
Multiple vulnerabilities in the Media Gateway Control Protocol (MGCP) inspection feature of Cisco Adaptive Security Appliance (ASA) Software and Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device.
The vulnerabilities are due to inefficient memory management. An attacker could exploit these vulnerabilities by sending crafted MGCP packets through an affected device. An exploit could allow the attacker to cause memory exhaustion resulting in a restart of an affected device, causing a DoS condition for traffic traversing the device.
Cisco has rel
Cisco
Cisco Adaptive Security Appliance Software and Firepower Threat Defense Software Media Gateway Control Protocol Denial of Service Vulnerabilities
vendor_cisco·CVSS 3.0
CVE-2020-3254 Cisco Adaptive Security Appliance Software and Firepower Threat Defense Software Media Gateway Control Protocol Denial of Service Vulnerabilities
CVE-2020-3254: Cisco Adaptive Security Appliance Software and Firepower Threat Defense Software Media Gateway Control Protocol Denial of Service Vulnerabilities
Multiple vulnerabilities in the Media Gateway Control Protocol (MGCP) inspection feature of Cisco Adaptive Security Appliance (ASA) Software and Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. The vulnerabilities are due to inefficient memory management. An attacker could exploit these vulnerabilities by sending crafted MGCP packets through an affected device. An exploit could allow the attacker to cause memory exhaustion resulting in a restart of an affected device, causing a DoS condition for traffic traversing the device.
No detection rules found.
No public exploits indexed.
2020-05-06
Published