CVE Vulnerabilities

CVE-2022-20854

Improper Handling of Exceptional Conditions

Published: Nov 15, 2022 | Modified: Jan 25, 2024
CVSS 3.x
7.5
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

A vulnerability in the processing of SSH connections of Cisco Firepower Management Center (FMC) and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to improper error handling when an SSH session fails to be established. An attacker could exploit this vulnerability by sending a high rate of crafted SSH connections to the instance. A successful exploit could allow the attacker to cause resource exhaustion, resulting in a reboot on the affected device.

Weakness

The product does not handle or incorrectly handles an exceptional condition.

Affected Software

Name Vendor Start Version End Version
Firepower_management_center Cisco 6.1.0 (including) 6.1.0.7 (including)
Firepower_management_center Cisco 6.2.0 (including) 6.2.0.6 (including)
Firepower_management_center Cisco 6.2.2 (including) 6.2.2.5 (including)
Firepower_management_center Cisco 6.2.3 (including) 6.2.3.18 (including)
Firepower_management_center Cisco 6.3.0 (including) 6.3.0.5 (including)
Firepower_management_center Cisco 6.4.0 (including) 6.4.0.15 (including)
Firepower_management_center Cisco 6.5.0 (including) 6.5.0.5 (including)
Firepower_management_center Cisco 6.7.0 (including) 6.7.0.3 (including)
Firepower_management_center Cisco 6.2.1 (including) 6.2.1 (including)
Firepower_management_center Cisco 6.6.0 (including) 6.6.0 (including)
Firepower_management_center Cisco 6.6.0.1 (including) 6.6.0.1 (including)
Firepower_management_center Cisco 6.6.1 (including) 6.6.1 (including)
Firepower_management_center Cisco 6.6.3 (including) 6.6.3 (including)
Firepower_management_center Cisco 6.6.4 (including) 6.6.4 (including)
Firepower_management_center Cisco 6.6.5 (including) 6.6.5 (including)
Firepower_management_center Cisco 6.6.5.1 (including) 6.6.5.1 (including)
Firepower_management_center Cisco 6.6.5.2 (including) 6.6.5.2 (including)
Firepower_management_center Cisco 7.0.0 (including) 7.0.0 (including)
Firepower_management_center Cisco 7.0.0.1 (including) 7.0.0.1 (including)
Firepower_management_center Cisco 7.0.1 (including) 7.0.1 (including)
Firepower_management_center Cisco 7.0.1.1 (including) 7.0.1.1 (including)
Firepower_management_center Cisco 7.0.2 (including) 7.0.2 (including)
Firepower_management_center Cisco 7.0.2.1 (including) 7.0.2.1 (including)
Firepower_management_center Cisco 7.0.3 (including) 7.0.3 (including)
Firepower_management_center Cisco 7.0.4 (including) 7.0.4 (including)

References