Impact
A logic error in the handling of DNS responses over TCP can cause the device’s DNS response parser to restart unexpectedly, leading to a reload of the firewall. This results in a denial of service by interrupting the device’s normal operation until it stabilises. The flaw is a signed‑to‑unsigned conversion error in the buffer size comparison logic, as identified in CWE‑195.
Affected Systems
Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software are affected. Specific version information is not provided in the advisory, so all current or earlier releases that implement TCP DNS parsing are potentially vulnerable.
Risk and Exploitability
The CVSS score of 6.8 indicates moderate severity. The EPSS score is less than 1%, and the vulnerability is not listed in CISA’s KEV catalog, suggesting a low probability of widespread exploitation. An attacker must be able to send a crafted DNS reply to the appliance, which typically requires control over the DNS server used by the appliance or a man‑in‑the‑middle position. The exploit is remote and unauthenticated but requires proximity to the device’s DNS traffic. Once triggered, the device reloads, causing a temporary denial of service.
OpenCVE Enrichment