CVE-2020-3528
Cisco Cisco Adaptive Security Appliance (ASA) Software, adaptive security appliance, secure firewall threat defense
A vulnerability in the OSPF Version 2 (OSPFv2) implementation of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause an affected device to reload, resulting in a denial of service (DoS) condition. The vulnerability is due to incomplete input validation when the affected software processes certain OSPFv2 packets with Link-Local Signaling (LLS) data. An attacker could exploit this vulnerability by sending a malformed OSPFv2 packet to an affected device. A successful exploit could allow the...
- CVSS
- 7.5
- EPSS
- 1.43% 71.2% percentile
- CISA KEV
- Not listed
- Published
- 2020.10.22