Impact
The vulnerability stems from improper buffer management in the TLS 1.3 implementation of Cisco Secure Firewall Threat Defense software. An unauthenticated attacker can send a crafted TLS 1.3 packet to a device’s listening socket, causing the LINA process to crash and forcing the device to reload. This results in an abrupt restart, exposing the system to a denial of service. The flaw is classified as CWE‑415, a flaw in memory handling that leads to process termination.
Affected Systems
Cisco Secure Firewall Threat Defense (FTD) Software is the only vendor and product identified as impacted. No specific version numbers were listed in the advisory, so all releases of the FTD product that include the TLS 1.3 implementation may be affected.
Risk and Exploitability
The CVSS score of 8.6 classifies the issue as high severity. The EPSS score indicates a very low probability of exploitation in the wild, and the vulnerability is not currently listed in CISA’s KEV catalog. Nevertheless, the attack vector can be remote and does not require authentication, making it actionable by external actors. If exploited, the device will unpredictably reload, disrupting network security services. The likely path involves an attacker sending a malicious TLS 1.3 packet before or after authentication, triggering the buffer overflow and crash.
OpenCVE Enrichment