← Back

CVE-2019-12700

nvd nist
Published: Oct 2, 2019Modified: Nov 26, 2024

JSON object

Loading...
6.5
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Exploitability: 2.8 / Impact: 3.6
Source: NVD

Description

A vulnerability in the configuration of the Pluggable Authentication Module (PAM) used in Cisco Firepower Threat Defense (FTD) Software, Cisco Firepower Management Center (FMC) Software, and Cisco FXOS Software could allow an authenticated, remote attacker to cause a denial of service (DoS) condition. The vulnerability is due to improper resource management in the context of user session management. An attacker could exploit this vulnerability by connecting to an affected system and performing many simultaneous successful Secure Shell (SSH) logins. A successful exploit could allow the attacker to exhaust system resources and cause the device to reload, resulting in a DoS condition. To exploit this vulnerability, the attacker needs valid user credentials on the system.

Affected (12)

4 products
Firepower 9300 Firmware
Firepower Threat Defense
Secure Firewall Management Center
Configuration A
2 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Cisco
Version r114
Version r241
Running on/withPlatform Versions
Cisco
Firepower 9300
All versions
Configuration B
3 vulnerable
Vulnerable SoftwareAffected Versions
Cisco
Up to 2.2
From 2.3 to 2.3.1.155
From 2.4 to 2.6.1.131
Configuration C
1 vulnerable · 2 platform
Vulnerable SoftwareAffected Versions
From 6.2.0 to 6.2.3.14
Running on/withPlatform Versions
Cisco
Firepower 1000
All versions
Cisco
Firepower 2100
All versions
Configuration D
6 vulnerable
Vulnerable SoftwareAffected Versions
Cisco
Up to 6.1.0
From 6.2.0 to 6.2.2.5
From 6.2.3 to 6.2.3.7
Cisco
Up to 6.1.0
From 6.2.0 to 6.2.3.14
From 6.2.3 to 6.2.3.7

Timeline

No history available yet.