CVE-2017-3887
MEDIUMCisco Firepower System Software < - DoS
Title source: llmDescription
A vulnerability in the detection engine that handles Secure Sockets Layer (SSL) packets for Cisco Firepower System Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition because the Snort process unexpectedly restarts. This vulnerability affects Cisco Firepower System Software prior to the first fixed release when it is configured with an SSL Decrypt-Resign policy. More Information: CSCvb62292. Known Affected Releases: 6.0.1 6.1.0 6.2.0. Known Fixed Releases: 6.2.0 6.1.0.2.
Scores
CVSS v3
5.9
EPSS
0.0056
EPSS Percentile
67.9%
Attack Vector
NETWORK
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
Classification
CWE
CWE-755
Status
draft
Affected Products (3)
cisco/firepower_threat_defense
cisco/firepower_threat_defense
cisco/firepower_threat_defense
Timeline
Published
Apr 07, 2017
Tracked Since
Feb 18, 2026