Impact
A remote, unauthenticated attacker can send a crafted SSL/TLS connection setup request that is parsed by the Snort 2 Detection Engine of Cisco Secure Firewall Threat Defense. The engine contains an incomplete validation of the SSL certificate, and when it processes the malformed request the Snort 2 Detection Engine restarts unexpectedly. The restart temporarily disables the firewall’s packet inspection and routing capability, causing a denial‑of‑service condition for traffic routed through the device.
Affected Systems
Cisco Secure Firewall Threat Defense (FTD) Software, specifically the Snort 2 Detection Engine. No specific version information is disclosed, so any released product that incorporates this engine is potentially vulnerable.
Risk and Exploitability
The CVSS base score is 5.8, indicating a moderate impact, while the EPSS of less than 1 % suggests a low likelihood of current exploitation. The vulnerability is not listed in the CISA KEV catalog. Exploitation requires the attacker to forge a valid‑looking SSL/TLS handshake and target the firewall from outside the network, implying a remote, unauthenticated attack vector.
OpenCVE Enrichment