CVE-2023-20070

CWE-2444 documents4 sources
Severity
4.0MEDIUM
EPSS
0.2%
top 53.03%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedNov 1

Description

A vulnerability in the TLS 1.3 implementation of the Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause the Snort 3 detection engine to unexpectedly restart. This vulnerability is due to a logic error in how memory allocations are handled during a TLS 1.3 session. Under specific, time-based constraints, an attacker could exploit this vulnerability by sending a crafted TLS 1.3 message sequence through an affected device. A successful exploit cou

CVSS vector

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:N/I:N/A:LExploitability: 2.2 | Impact: 1.4

Affected Packages2 packages

NVDcisco/firepower_threat_defense7.2.0, 7.2.0.1+1

🔴Vulnerability Details

2
CVEList
CVE-2023-20070: A vulnerability in the TLS 12023-11-01
GHSA
GHSA-9929-5h8g-7gv5: A vulnerability in the TLS 12023-11-01

📋Vendor Advisories

1
Cisco
Cisco Firepower Threat Defense Software Snort 3 Detection Engine Denial of Service Vulnerability2023-11-01
CVE-2023-20070 (MEDIUM CVSS 4) | A vulnerability in the TLS 1.3 impl | cvebase.io