Impact
A flaw in the EIGRP implementation on Cisco Secure Firewall Adaptive Security Appliance and Threat Defense software allows an unauthenticated attacker on an adjacent network to send crafted EIGRP updates at high rate, triggering a memory leak that eventually forces the device to reload, resulting in a denial of service. The weakness is a memory management issue (CWE-401).
Affected Systems
Vulnerable devices include Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software. The issue can be exploited by any adjacent attacker without authentication, regardless of the device’s configuration or other security controls.
Risk and Exploitability
The CVSS v3 score of 7.4 indicates a high impact failure, but the EPSS score of less than 1% and absence from the CISA KEV list suggest low to moderate current exploitation likelihood. The attack vector is network-based from a neighbor; an attacker only needs to deliver EIGRP update packets. Given the low exploitation probability, the risk is moderate, but immediate patching is recommended to prevent a potential do‑of‑service event.
OpenCVE Enrichment