← Back

CVE-2020-27124

nvd nist
Published: Nov 18, 2024Modified: Aug 1, 2025

JSON object

Loading...
8.6
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H
Exploitability: 3.9 / Impact: 4.0
Source: psirt@cisco.com (Secondary)

Description

A vulnerability in the SSL/TLS handler of Cisco Adaptive Security Appliance (ASA) Software could allow an unauthenticated, remote attacker to cause the affected device to reload unexpectedly, leading to a denial of service (DoS) condition. The vulnerability is due to improper error handling on established SSL/TLS connections. An attacker could exploit this vulnerability by establishing an SSL/TLS connection with the affected device and then sending a malicious SSL/TLS message within that connection. A successful exploit could allow the attacker to cause the device to reload.Cisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability.

Affected (3)

1 product
Configuration A
3 vulnerable
Vulnerable SoftwareAffected Versions
Cisco
Version 9.13.1.12
Version 9.13.1.13
Version 9.14.1.10

Timeline

No history available yet.