Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2019-1700

Опубликовано: 21 фев. 2019
Источник: nvd
CVSS3: 6.1
CVSS2: 5.7
EPSS Низкий

Описание

A vulnerability in field-programmable gate array (FPGA) ingress buffer management for the Cisco Firepower 9000 Series with the Cisco Firepower 2-port 100G double-width network module (PID: FPR9K-DNM-2X100G) could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) condition. Manual intervention may be required before a device will resume normal operations. The vulnerability is due to a logic error in the FPGA related to the processing of different types of input packets. An attacker could exploit this vulnerability by being on the adjacent subnet and sending a crafted sequence of input packets to a specific interface on an affected device. A successful exploit could allow the attacker to cause a queue wedge condition on the interface. When a wedge occurs, the affected device will stop processing any additional packets that are received on the wedged interface. Version 2.2 is affected.

Уязвимые конфигурации

Конфигурация 1

Одновременно

cpe:2.3:o:cisco:firepower_9000_firmware:2.2\(200.8\):*:*:*:*:*:*:*
cpe:2.3:h:cisco:firepower_9000:-:*:*:*:*:*:*:*

EPSS

Процентиль: 35%
0.00145
Низкий

6.1 Medium

CVSS3

5.7 Medium

CVSS2

Дефекты

CWE-399
CWE-399

Связанные уязвимости

CVSS3: 6.1
github
больше 3 лет назад

A vulnerability in field-programmable gate array (FPGA) ingress buffer management for the Cisco Firepower 9000 Series with the Cisco Firepower 2-port 100G double-width network module (PID: FPR9K-DNM-2X100G) could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) condition. Manual intervention may be required before a device will resume normal operations. The vulnerability is due to a logic error in the FPGA related to the processing of different types of input packets. An attacker could exploit this vulnerability by being on the adjacent subnet and sending a crafted sequence of input packets to a specific interface on an affected device. A successful exploit could allow the attacker to cause a queue wedge condition on the interface. When a wedge occurs, the affected device will stop processing any additional packets that are received on the wedged interface. Version 2.2 is affected.

CVSS3: 6.1
fstec
почти 7 лет назад

Уязвимость программируемой логической интегральной схемы управляющей входным буфером микропрограммного обеспечения межсетевых экранов Cisco Firepower 9000 Series, позволяющая нарушителю вызвать отказ в обслуживании

EPSS

Процентиль: 35%
0.00145
Низкий

6.1 Medium

CVSS3

5.7 Medium

CVSS2

Дефекты

CWE-399
CWE-399