CVE-2022-20927

A vulnerability in the SSL/TLS client of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an authenticated, remote attacker to cause a denial of service (DoS) condition on an affected device.

 This vulnerability is due to improper memory management when a device initiates SSL/TLS connections. An attacker could exploit this vulnerability by ensuring that the device will connect to an SSL/TLS server that is using specific encryption parameters. A successful exploit could allow the attacker to cause the affected device to unexpectedly reload, resulting in a DoS condition.
Classic Buffer Overflow
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
7.7 HIGH
NETWORK
LOW
LOW
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H
ciscoCNA
7.7 HIGH
NETWORK
LOW
LOW
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 30%
VendorProductVersion
ciscoadaptive_security_appliance_software
9.13.1
ciscoadaptive_security_appliance_software
9.13.1.2
ciscoadaptive_security_appliance_software
9.13.1.7
ciscoadaptive_security_appliance_software
9.13.1.10
ciscoadaptive_security_appliance_software
9.13.1.12
ciscoadaptive_security_appliance_software
9.13.1.13
ciscoadaptive_security_appliance_software
9.13.1.16
ciscoadaptive_security_appliance_software
9.13.1.19
ciscoadaptive_security_appliance_software
9.13.1.21
ciscoadaptive_security_appliance_software
9.14.1
ciscoadaptive_security_appliance_software
9.14.1.10
ciscoadaptive_security_appliance_software
9.14.1.15
ciscoadaptive_security_appliance_software
9.14.1.19
ciscoadaptive_security_appliance_software
9.14.1.30
ciscoadaptive_security_appliance_software
9.14.2
ciscoadaptive_security_appliance_software
9.14.2.4
ciscoadaptive_security_appliance_software
9.14.2.8
ciscoadaptive_security_appliance_software
9.14.2.13
ciscoadaptive_security_appliance_software
9.14.2.15
ciscoadaptive_security_appliance_software
9.14.3
ciscoadaptive_security_appliance_software
9.14.3.1
ciscoadaptive_security_appliance_software
9.14.3.9
ciscoadaptive_security_appliance_software
9.14.3.11
ciscoadaptive_security_appliance_software
9.14.3.13
ciscoadaptive_security_appliance_software
9.14.3.15
ciscoadaptive_security_appliance_software
9.14.3.18
ciscoadaptive_security_appliance_software
9.15.1
ciscoadaptive_security_appliance_software
9.15.1.1
ciscoadaptive_security_appliance_software
9.15.1.7
ciscoadaptive_security_appliance_software
9.15.1.10
ciscoadaptive_security_appliance_software
9.15.1.15
ciscoadaptive_security_appliance_software
9.15.1.16
ciscoadaptive_security_appliance_software
9.15.1.17
ciscoadaptive_security_appliance_software
9.15.1.21
ciscofirepower_threat_defense
6.5.0 ≤
𝑥
≤ 6.5.0.5
ciscofirepower_threat_defense
6.7.0 ≤
𝑥
≤ 6.7.0.3
ciscofirepower_threat_defense
6.6.0
ciscofirepower_threat_defense
6.6.0.1
ciscofirepower_threat_defense
6.6.1
ciscofirepower_threat_defense
6.6.3
ciscofirepower_threat_defense
6.6.4
ciscofirepower_threat_defense
6.6.5
ciscofirepower_threat_defense
6.6.5.1
ciscofirepower_services_software_for_asa
-
𝑥
= Vulnerable software versions