Impact
A flaw in the sftunnel inter‑device protocol of Cisco Secure Firewall Management Center and Cisco Secure Firewall Threat Defense allows an attacker to send specially crafted TLS frames during connection setup, causing the application to fail to release memory allocations. This results in a progressive depletion of available memory that can halt the device or force it to restart, producing a denial of service outcome. The vulnerability arises from improper resource cleanup during TLS handshake and can be triggered without any prior authentication.
Affected Systems
The vulnerability affects Cisco Secure Firewall Management Center (FMC) and Cisco Secure Firewall Threat Defense (FTD) software. Any managed device running either FMC or FTD and using the sftunnel TLS communication channel is potentially compromised. The impact is limited to systems that have this inter‑device protocol active.
Risk and Exploitability
The CVSS score of 8.6 indicates a high severity level. The EPSS score of less than 1% suggests that the probability of exploitation in the wild is low, and the vulnerability is not listed in the CISA KEV catalog. Attackers can remotely send crafted TLS frames without authentication, making the vector network‑based and potentially automated. Successful exploitation would require only communication to the target device’s sftunnel port and would not require any privileged access.
OpenCVE Enrichment