CVE-2020-3577
Cisco Cisco Firepower Threat Defense Software, secure firewall threat defense
A vulnerability in the ingress packet processing path of Cisco Firepower Threat Defense (FTD) Software for interfaces that are configured either as Inline Pair or in Passive mode could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) condition. The vulnerability is due to insufficient validation when Ethernet frames are processed. An attacker could exploit this vulnerability by sending malicious Ethernet frames through an affected device. A successful exploit could allow the attacker do either of the following: Fill the /ngfw partition on the device: A full /ng...
- CVSS
- 7.4
- EPSS
- 0.43% 36.3% percentile
- CISA KEV
- Not listed
- Published
- 2020.10.22