CVE-2022-20767

HIGH

Cisco Firepower Threat Defense - DoS

Title source: llm
STIX 2.1

Description

A vulnerability in the Snort rule evaluation function of Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. The vulnerability is due to improper handling of the DNS reputation enforcement rule. An attacker could exploit this vulnerability by sending crafted UDP packets through an affected device to force a buildup of UDP connections. A successful exploit could allow the attacker to cause traffic that is going through the affected device to be dropped, resulting in a DoS condition. Note: This vulnerability only affects Cisco FTD devices that are running Snort 3.

References (1)

Core 1
Core References

Scores

CVSS v3 8.6
EPSS 0.0135
EPSS Percentile 80.3%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact partial

Details

CWE
CWE-399 CWE-770
Status published
Products (2)
cisco/firepower_threat_defense 7.1.0
cisco/firepower_threat_defense < 7.0.2
Published May 03, 2022
Tracked Since Feb 18, 2026