CVE-2023-20244

CVSS 3.1 Score 8.6 of 10 (high)

Details

Published Nov 1, 2023
Updated: Jan 25, 2024
CWE ID 771

Summary

CVE-2023-20244 is a newly discovered vulnerability that impacts the internal packet processing of Cisco Firepower Threat Defense (FTD) Software on Cisco Firepower 2100 Series Firewalls. An unauthenticated, remote attacker can exploit this vulnerability by sending a series of maliciously crafted packets to an affected device, resulting in a denial of service (DoS) condition. The vulnerability arises due to the software's improper handling of certain packets sent to the inspection engine. Successful exploitation can lead to the depletion of all 9,472 byte blocks on the device, causing traffic loss or an unexpected reload of the device. Affected devices may require manual reloading to recover from this state.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share

Affected Products

  • Cisco Firepower Threat Defense

Affected Vendors

  • Cisco Systems Inc