CVE-2020-3305
HIGHCisco Adaptive Security Appliance and Firepower Threat Defense - Denial of Service via BGP Packet Processing
Title source: llmDescription
A vulnerability in the implementation of the Border Gateway Protocol (BGP) module in Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition. The vulnerability is due to incorrect processing of certain BGP packets. An attacker could exploit this vulnerability by sending a crafted BGP packet. A successful exploit could allow the attacker to cause a DoS condition on the affected device.
References (1)
Core 1
Core References
Vendor Advisory vendor-advisory
x_refsource_cisco
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-asa-dos-P43GCE5j
Scores
CVSS v3
7.5
EPSS
0.0060
EPSS Percentile
69.6%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
partial
Details
CWE
CWE-400
Status
published
Products (3)
cisco/adaptive_security_appliance
< 9.6.4.36
cisco/adaptive_security_appliance_software
9.7 - 9.8.4.10
cisco/firepower_threat_defense
< 6.3.0.5
Published
May 06, 2020
Tracked Since
Feb 18, 2026