CVE-2020-3554
Cisco Cisco Adaptive Security Appliance (ASA) Software, adaptive security appliance, secure firewall threat defense
A vulnerability in the TCP packet processing of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. The vulnerability is due to a memory exhaustion condition. An attacker could exploit this vulnerability by sending a high rate of crafted TCP traffic through an affected device. A successful exploit could allow the attacker to exhaust device resources, resulting in a DoS condition for traffic transiting the affected device.
- CVSS
- 7.5
- EPSS
- 2.67% 84.7% percentile
- CISA KEV
- Not listed
- Published
- 2020.10.22