CVE-2020-3436

HIGHCVSS 8.6/10EPSS 1.90%

Last modified

CVE-2020-3436 is a high-severity vulnerability rated 8.6/10 on the CVSS scale. A vulnerability in the web services interface of Cisco Adaptive Security Appliance (ASA) and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to upload arbitrary-sized files to specific folders on an affected device, which could lead to an unexpected device reload. The vulnerability exists because the affected software does not efficiently handle the writing of large files to specific folders on the local file system. EPSS estimates a 1.90% chance of exploitation in the next 30 days.

Description

A vulnerability in the web services interface of Cisco Adaptive Security Appliance (ASA) and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to upload arbitrary-sized files to specific folders on an affected device, which could lead to an unexpected device reload. The vulnerability exists because the affected software does not efficiently handle the writing of large files to specific folders on the local file system. An attacker could exploit this vulnerability by uploading files to those specific folders. A successful exploit could allow the attacker to write a file that triggers a watchdog timeout, which would cause the device to unexpectedly reload, causing a denial of service (DoS) condition.

Metrics

CVSS 3.1
8.6/10

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H

EPSS Probability
1.90%

77.0th percentile

Probability of exploitation in the next 30 days. Learn more

Weakness Enumeration

Affected Software

VendorProductVersions
CiscoAdaptive Security Appliance< 9.6.4.45
CiscoFirepower Threat Defense<= 6.2.2
CiscoFirepower Threat Defense>= 6.3.0, < 6.3.0.6
CiscoFirepower Threat Defense>= 6.4.0, < 6.4.0.10
CiscoFirepower Threat Defense>= 6.5.0, < 6.5.0.5
CiscoFirepower Threat Defense6.6.0
CiscoAdaptive Security Appliance Software>= 9.8.0, < 9.8.4.25
CiscoAdaptive Security Appliance Software>= 9.9.0, < 9.9.2.80
CiscoAdaptive Security Appliance Software>= 9.10.0, < 9.10.1.44
CiscoAdaptive Security Appliance Software>= 9.12.0, < 9.12.4.2
CiscoAdaptive Security Appliance Software>= 9.13.0, < 9.13.1.12
CiscoAdaptive Security Appliance Software>= 9.14.0, < 9.14.1.15

References

Timeline

Published
Last Modified
Status
Modified

Frequently Asked Questions

What is CVE-2020-3436?
A vulnerability in the web services interface of Cisco Adaptive Security Appliance (ASA) and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to upload arbitrary-sized files to specific folders on an affected device, which could lead to an unexpected device reload. The vulnerability exists because the affected software does not efficiently handle the writing of large files to specific folders on the local file system. An attacker could exploit this vulnerability by uploading files to those specific folders. A successful exploit could allow the attacker to write a file that triggers a watchdog timeout, which would cause the device to unexpectedly reload, causing a denial of service (DoS) condition.
How severe is CVE-2020-3436?
CVE-2020-3436 has a CVSS score of 8.6/10 (HIGH severity). The EPSS model estimates a 1.90% probability of exploitation in the next 30 days.
How do I fix CVE-2020-3436?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2020-3436?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST