Impact
The vulnerability arises from improper rate limiting for syslog message 419002 in Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Secure Firewall Threat Defense (FTD) Software. It permits an unauthenticated, remote attacker to flood the device with TCP SYN packets, leading the system to consume excessive CPU resources and degrade performance into a denial of service state. The weakness is classified as CWE-835, indicating that the internal counter or loop logic does not account for input limits, allowing a resource exhaustion scenario.
Affected Systems
This flaw affects Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software. Vulnerable versions are those that have not yet applied the rate‑limiting fix for syslog message 419002; the exact version range is not disclosed in the public advisory.
Risk and Exploitability
The CVSS score of 8.6 points to a high‑severity impact, while the EPSS score of less than 1% indicates a low probability of exploitation at the time of analysis. The vulnerability is not listed in the CISA KEV catalog. The attack path is straightforward: an unauthenticated attacker sends a SYN flood directed at the device, triggering the flawed rate limiting routine and causing CPU exhaustion. Because the exploit requires only flooding a standard network port with SYN packets, an adversary with network access can readily carry it out without special privileges or software.
OpenCVE Enrichment