← Back

CVE-2022-20751

nvd nist
Published: May 3, 2022Modified: Nov 21, 2024

JSON object

Loading...
7.5
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Exploitability: 3.9 / Impact: 3.6
Source: NVD

Description

A vulnerability in the Snort detection engine integration for Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause unlimited memory consumption, which could lead to a denial of service (DoS) condition on an affected device. This vulnerability is due to insufficient memory management for certain Snort events. An attacker could exploit this vulnerability by sending a series of crafted IP packets that would generate specific Snort events on an affected device. A sustained attack could cause an out of memory condition on the affected device. A successful exploit could allow the attacker to interrupt all traffic flowing through the affected device. In some circumstances, the attacker may be able to cause the device to reload, resulting in a DoS condition.

Affected (4)

1 product
Firepower Threat Defense
Configuration A
4 vulnerable · 22 platform
Vulnerable SoftwareAffected Versions
Cisco
Before 6.4.0.15
From 6.5.0 to 6.6.5.2
From 7.0.0 to 7.0.2
Version 7.1.0.0
Running on/withPlatform Versions
Cisco
Firepower 1000
All versions
Cisco
Firepower 1010
All versions
Cisco
Firepower 1020
All versions
Cisco
Firepower 1030
All versions
Cisco
Firepower 1040
All versions
Cisco
Firepower 1120
All versions
Cisco
Firepower 1140
All versions
Cisco
Firepower 1150
All versions
Cisco
Firepower 2100
All versions
Cisco
Firepower 2110
All versions
Cisco
Firepower 2120
All versions
Cisco
Firepower 2130
All versions
Cisco
Firepower 2140
All versions
Cisco
Firepower 4100
All versions
Cisco
Firepower 4110
All versions
Cisco
Firepower 4112
All versions
Cisco
Firepower 4115
All versions
Cisco
Firepower 4120
All versions
Cisco
Firepower 4125
All versions
Cisco
Firepower 4140
All versions
Cisco
Firepower 4145
All versions
Cisco
Firepower 4150
All versions

Timeline

No history available yet.