CVE-2020-3188

medium Cisco
CVSS v3 Base Score
5.3
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
EPSS Score
1.7%
Exploitation probability in 30 days
Top 25% most likely to be exploited
Attack Characteristics
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Confidentiality
None
Integrity
None
Availability
Low
Published: May 6, 2020 (2314 days ago)
Last Modified: August 11, 2026
Vendor: Cisco
Source: NVD

Description

A vulnerability in how Cisco Firepower Threat Defense (FTD) Software handles session timeouts for management connections could allow an unauthenticated, remote attacker to cause a buildup of remote management connections to an affected device, which could result in a denial of service (DoS) condition. The vulnerability exists because the default session timeout period for specific to-the-box remote management connections is too long. An attacker could exploit this vulnerability by sending a large and sustained number of crafted remote management connections to an affected device, resulting in a buildup of those connections over time. A successful exploit could allow the attacker to cause the remote management interface or Cisco Firepower Device Manager (FDM) to stop responding and cause other management functions to go offline, resulting in a DoS condition. The user traffic that is flowing through the device would not be affected, and the DoS condition would be isolated to remote management only.

CWE

CWE-399

Affected Products

cisco secure firewall threat defensecisco asa 5505 firmwarecisco asa 5510 firmwarecisco asa 5512-x firmwarecisco asa 5515-x firmwarecisco asa 5520 firmwarecisco asa 5525-x firmwarecisco asa 5540 firmwarecisco asa 5545-x firmwarecisco asa 5550 firmware

References