Threat Advisory

Cisco Secure Firewall Snort 2 Experiences Denial of Service Vulnerability

Threat: Vulnerability
Targeted Region: Global
Targeted Sector: Technology & IT
Criticality: Medium
[subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

A medium-severity vulnerability exists in the SSL/TLS certificate parsing functionality within the Snort 2 Detection Engine of Cisco Secure Firewall Threat Defense Software. This flaw allows an unauthenticated, remote attacker to cause the Snort 2 Detection Engine to restart due to incomplete validation of the SSL certificate. An attacker could exploit this vulnerability by sending a crafted SSL connection setup request to be parsed by Snort 2, resulting in a denial-of-service (DoS) condition. The CVSS score for this vulnerability is 5.8 and it falls under CWE-805, which involves an incorrect handling of protocol fragments. This vulnerability has been addressed through software updates from Cisco, with no workarounds available to mitigate its impact. Affected products include Open Source Snort 2 and Cisco Secure FTD Software if Snort 2 is configured, while other Cisco products such as Cisco Cyber Vision and Cisco Secure Firewall Adaptive Security Appliance (ASA) Software are confirmed not vulnerable.

RECOMMENDATION:

We recommend you to refer below link: https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ftd-snort2-ssldos-Mw7WYX9c?vs_f=Cisco%20Security%20Advisory%26vs_cat=Security%20Intelligence%26vs_type=RSS%26vs_p=Cisco%20Secure%20Firewall%20Threat%20Defense%20Software%20Snort%202%20SSL/TLS%20Denial%20of%20Service%20Vulnerability%26vs_k=1[/subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

A medium-severity vulnerability exists in the SSL/TLS certificate parsing functionality within the Snort 2 Detection Engine of Cisco Secure Firewall Threat Defense Software. This flaw allows an unauthenticated, remote attacker to cause the Snort 2 Detection Engine to restart due to incomplete validation of the SSL certificate. An attacker could exploit this vulnerability by sending a crafted SSL connection setup request to be parsed by Snort 2, resulting in a denial-of-service (DoS) condition. The CVSS score for this vulnerability is 5.8 and it falls under CWE-805, which involves an incorrect handling of protocol fragments. This vulnerability has been addressed through software updates from Cisco, with no workarounds available to mitigate its impact. Affected products include Open Source Snort 2 and Cisco Secure FTD Software if Snort 2 is configured, while other Cisco products such as Cisco Cyber Vision and Cisco Secure Firewall Adaptive Security Appliance (ASA) Software are confirmed not vulnerable.

RECOMMENDATION:

We recommend you to refer below link: https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ftd-snort2-ssldos-Mw7WYX9c?vs_f=Cisco%20Security%20Advisory%26vs_cat=Security%20Intelligence%26vs_type=RSS%26vs_p=Cisco%20Secure%20Firewall%20Threat%20Defense%20Software%20Snort%202%20SSL/TLS%20Denial%20of%20Service%20Vulnerability%26vs_k=1[emaillocker id="1283"]

REFERENCES:

The following reports contain further technical details:

[/emaillocker]
crossmenu