CVE-2020-3303
Severity CVSS v4.0:
Pending analysis
Type:
CWE-400
Uncontrolled Resource Consumption ('Resource Exhaustion')
Publication date:
06/05/2020
Last modified:
16/08/2023
Description
A vulnerability in the Internet Key Exchange version 1 (IKEv1) feature of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition. The vulnerability is due to improper management of system memory. An attacker could exploit this vulnerability by sending malicious IKEv1 traffic to an affected device. A successful exploit could allow the attacker to cause a DoS condition on the affected device.
Impact
Base Score 3.x
7.50
Severity 3.x
HIGH
Base Score 2.0
7.80
Severity 2.0
HIGH
Vulnerable products and versions
CPE | From | Up to |
---|---|---|
cpe:2.3:a:cisco:adaptive_security_appliance:*:*:*:*:*:*:*:* | 9.6.4.36 (excluding) | |
cpe:2.3:o:cisco:adaptive_security_appliance_software:*:*:*:*:*:*:*:* | 9.7 (including) | 9.8.4.10 (excluding) |
cpe:2.3:o:cisco:adaptive_security_appliance_software:*:*:*:*:*:*:*:* | 9.9 (including) | 9.10.1.30 (excluding) |
cpe:2.3:o:cisco:adaptive_security_appliance_software:*:*:*:*:*:*:*:* | 9.12 (including) | 9.12.2.9 (excluding) |
cpe:2.3:h:cisco:asa_5505:-:*:*:*:*:*:*:* | ||
cpe:2.3:h:cisco:asa_5510:-:*:*:*:*:*:*:* | ||
cpe:2.3:h:cisco:asa_5512-x:-:*:*:*:*:*:*:* | ||
cpe:2.3:h:cisco:asa_5515-x:-:*:*:*:*:*:*:* | ||
cpe:2.3:h:cisco:asa_5520:-:*:*:*:*:*:*:* | ||
cpe:2.3:h:cisco:asa_5525-x:-:*:*:*:*:*:*:* | ||
cpe:2.3:h:cisco:asa_5550:-:*:*:*:*:*:*:* | ||
cpe:2.3:h:cisco:asa_5555-x:-:*:*:*:*:*:*:* | ||
cpe:2.3:h:cisco:asa_5580:-:*:*:*:*:*:*:* | ||
cpe:2.3:h:cisco:asa_5585-x:-:*:*:*:*:*:*:* | ||
cpe:2.3:a:cisco:firepower_threat_defense:*:*:*:*:*:*:*:* | 6.3.0.5 (excluding) |
To consult the complete list of CPE names with products and versions, see this page