CVE-2023-20031Heap Inspection in Cisco Firepower Threat Defense Software

CWE-244Heap Inspection4 documents4 sources
Severity
5.4MEDIUMNVD
CNA4.0
EPSS
0.0%
top 95.72%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedNov 1

Description

A vulnerability in the SSL/TLS certificate handling of Snort 3 Detection Engine integration with Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause the Snort 3 detection engine to restart. This vulnerability is due to a logic error that occurs when an SSL/TLS certificate that is under load is accessed when it is initiating an SSL connection. Under specific, time-based constraints, an attacker could exploit this vulnerability by sending a high r

CVSS vector

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:N/I:L/A:LExploitability: 2.2 | Impact: 2.7

Affected Packages2 packages

🔴Vulnerability Details

2
CVEList
CVE-2023-20031: A vulnerability in the SSL/TLS certificate handling of Snort 3 Detection Engine integration with Cisco Firepower Threat Defense (FTD) Software could a2023-11-01
GHSA
GHSA-qg6w-hxqj-gmgx: A vulnerability in the SSL/TLS certificate handling of Snort 3 Detection Engine integration with Cisco Firepower Threat Defense (FTD) Software could a2023-11-01

📋Vendor Advisories

1
Cisco
Cisco Firepower Threat Defense Software SSL and Snort 3 Detection Engine Bypass and Denial of Service Vulnerability2023-11-01
CVE-2023-20031 — Heap Inspection in Cisco | cvebase