ID

VAR-202204-1974


CVE

CVE-2022-20760


TITLE

Cisco Adaptive Security Appliance  software   and  Firepower Threat Defense  Resource Exhaustion Vulnerability in Software

Trust: 0.8

sources: JVNDB: JVNDB-2022-010592

DESCRIPTION

A vulnerability in the DNS inspection handler of Cisco Adaptive Security Appliance (ASA) Software and Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause a denial of service condition (DoS) on an affected device. This vulnerability is due to a lack of proper processing of incoming requests. An attacker could exploit this vulnerability by sending crafted DNS requests at a high rate to an affected device. A successful exploit could allow the attacker to cause the device to stop responding, resulting in a DoS condition. The platform provides features such as highly secure access to data and network resources. Cisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability. This advisory is available at the following link:tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-asaftd-dos-nJVAwOeq This advisory is part of the April 2022 release of the Cisco ASA, FTD, and FMC Security Advisory Bundled publication. For a complete list of the advisories and links to them, see Cisco Event Response: April 2022 Cisco ASA, FMC, and FTD Software Security Advisory Bundled Publication

Trust: 1.8

sources: NVD: CVE-2022-20760 // JVNDB: JVNDB-2022-010592 // VULHUB: VHN-405313 // VULMON: CVE-2022-20760

AFFECTED PRODUCTS

vendor:ciscomodel:firepower threat defensescope:gteversion:7.0.0

Trust: 1.0

vendor:ciscomodel:adaptive security appliance softwarescope:gteversion:9.15.0

Trust: 1.0

vendor:ciscomodel:firepower threat defensescope:gteversion:6.5.0

Trust: 1.0

vendor:ciscomodel:adaptive security appliance softwarescope:ltversion:9.16.2.14

Trust: 1.0

vendor:ciscomodel:adaptive security appliance softwarescope:gteversion:9.16.0

Trust: 1.0

vendor:ciscomodel:firepower threat defensescope:ltversion:7.0.2

Trust: 1.0

vendor:ciscomodel:firepower threat defensescope:ltversion:6.4.0.15

Trust: 1.0

vendor:ciscomodel:adaptive security appliance softwarescope:gteversion:9.13.0

Trust: 1.0

vendor:ciscomodel:firepower threat defensescope:eqversion:7.1.0

Trust: 1.0

vendor:ciscomodel:adaptive security appliance softwarescope:ltversion:9.17.1.7

Trust: 1.0

vendor:ciscomodel:adaptive security appliance softwarescope:gteversion:9.17.0

Trust: 1.0

vendor:ciscomodel:adaptive security appliance softwarescope:ltversion:9.14.4

Trust: 1.0

vendor:ciscomodel:adaptive security appliance softwarescope:ltversion:9.15.1.21

Trust: 1.0

vendor:ciscomodel:firepower threat defensescope:ltversion:6.6.5.2

Trust: 1.0

vendor:ciscomodel:adaptive security appliance softwarescope:ltversion:9.12.4.38

Trust: 1.0

vendor:シスコシステムズmodel:cisco firepower threat defense ソフトウェアscope: - version: -

Trust: 0.8

vendor:シスコシステムズmodel:cisco adaptive security appliance ソフトウェアscope: - version: -

Trust: 0.8

sources: JVNDB: JVNDB-2022-010592 // NVD: CVE-2022-20760

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2022-20760
value: HIGH

Trust: 1.0

ykramarz@cisco.com: CVE-2022-20760
value: HIGH

Trust: 1.0

NVD: CVE-2022-20760
value: HIGH

Trust: 0.8

CNNVD: CNNVD-202204-4507
value: HIGH

Trust: 0.6

VULHUB: VHN-405313
value: HIGH

Trust: 0.1

nvd@nist.gov: CVE-2022-20760
severity: HIGH
baseScore: 7.8
vectorString: AV:N/AC:L/AU:N/C:N/I:N/A:C
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: NONE
integrityImpact: NONE
availabilityImpact: COMPLETE
exploitabilityScore: 10.0
impactScore: 6.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.8

VULHUB: VHN-405313
severity: HIGH
baseScore: 7.8
vectorString: AV:N/AC:L/AU:N/C:N/I:N/A:C
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: NONE
integrityImpact: NONE
availabilityImpact: COMPLETE
exploitabilityScore: 10.0
impactScore: 6.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.1

nvd@nist.gov: CVE-2022-20760
baseSeverity: HIGH
baseScore: 7.5
vectorString: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
attackVector: NETWORK
attackComplexity: LOW
privilegesRequired: NONE
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: NONE
integrityImpact: NONE
availabilityImpact: HIGH
exploitabilityScore: 3.9
impactScore: 3.6
version: 3.1

Trust: 1.0

ykramarz@cisco.com: CVE-2022-20760
baseSeverity: HIGH
baseScore: 8.6
vectorString: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H
attackVector: NETWORK
attackComplexity: LOW
privilegesRequired: NONE
userInteraction: NONE
scope: CHANGED
confidentialityImpact: NONE
integrityImpact: NONE
availabilityImpact: HIGH
exploitabilityScore: 3.9
impactScore: 4.0
version: 3.1

Trust: 1.0

NVD: CVE-2022-20760
baseSeverity: HIGH
baseScore: 7.5
vectorString: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
attackVector: NETWORK
attackComplexity: LOW
privilegesRequired: NONE
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: NONE
integrityImpact: NONE
availabilityImpact: HIGH
exploitabilityScore: NONE
impactScore: NONE
version: 3.0

Trust: 0.8

sources: VULHUB: VHN-405313 // JVNDB: JVNDB-2022-010592 // CNNVD: CNNVD-202204-4507 // NVD: CVE-2022-20760 // NVD: CVE-2022-20760

PROBLEMTYPE DATA

problemtype:CWE-400

Trust: 1.1

problemtype:Resource exhaustion (CWE-400) [NVD evaluation ]

Trust: 0.8

sources: VULHUB: VHN-405313 // JVNDB: JVNDB-2022-010592 // NVD: CVE-2022-20760

THREAT TYPE

remote

Trust: 0.6

sources: CNNVD: CNNVD-202204-4507

TYPE

resource management error

Trust: 0.6

sources: CNNVD: CNNVD-202204-4507

PATCH

title:cisco-sa-asaftd-dos-nJVAwOequrl:https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-asaftd-dos-nJVAwOeq

Trust: 0.8

title:Multiple Cisco Product resource management error vulnerability fixesurl:http://www.cnnvd.org.cn/web/xxk/bdxqById.tag?id=191573

Trust: 0.6

title:Cisco: Cisco Adaptive Security Appliance Software and Firepower Threat Defense Software DNS Inspection Denial of Service Vulnerabilityurl:https://vulmon.com/vendoradvisory?qidtp=cisco_security_advisories_and_alerts_ciscoproducts&qid=cisco-sa-asaftd-dos-nJVAwOeq

Trust: 0.1

sources: VULMON: CVE-2022-20760 // JVNDB: JVNDB-2022-010592 // CNNVD: CNNVD-202204-4507

EXTERNAL IDS

db:NVDid:CVE-2022-20760

Trust: 3.4

db:JVNDBid:JVNDB-2022-010592

Trust: 0.8

db:AUSCERTid:ESB-2022.1909

Trust: 0.6

db:CS-HELPid:SB2022042739

Trust: 0.6

db:CNNVDid:CNNVD-202204-4507

Trust: 0.6

db:CNVDid:CNVD-2022-44689

Trust: 0.1

db:VULHUBid:VHN-405313

Trust: 0.1

db:VULMONid:CVE-2022-20760

Trust: 0.1

sources: VULHUB: VHN-405313 // VULMON: CVE-2022-20760 // JVNDB: JVNDB-2022-010592 // CNNVD: CNNVD-202204-4507 // NVD: CVE-2022-20760

REFERENCES

url:https://tools.cisco.com/security/center/content/ciscosecurityadvisory/cisco-sa-asaftd-dos-njvawoeq

Trust: 2.4

url:https://nvd.nist.gov/vuln/detail/cve-2022-20760

Trust: 0.8

url:https://vigilance.fr/vulnerability/cisco-asa-denial-of-service-via-dns-inspection-38167

Trust: 0.6

url:https://www.cybersecurity-help.cz/vdb/sb2022042739

Trust: 0.6

url:https://www.auscert.org.au/bulletins/esb-2022.1909

Trust: 0.6

url:https://cxsecurity.com/cveshow/cve-2022-20760/

Trust: 0.6

sources: VULHUB: VHN-405313 // VULMON: CVE-2022-20760 // JVNDB: JVNDB-2022-010592 // CNNVD: CNNVD-202204-4507 // NVD: CVE-2022-20760

SOURCES

db:VULHUBid:VHN-405313
db:VULMONid:CVE-2022-20760
db:JVNDBid:JVNDB-2022-010592
db:CNNVDid:CNNVD-202204-4507
db:NVDid:CVE-2022-20760

LAST UPDATE DATE

2024-08-14T13:22:23.075000+00:00


SOURCES UPDATE DATE

db:VULHUBid:VHN-405313date:2022-05-12T00:00:00
db:JVNDBid:JVNDB-2022-010592date:2023-08-16T05:23:00
db:CNNVDid:CNNVD-202204-4507date:2022-05-13T00:00:00
db:NVDid:CVE-2022-20760date:2023-11-07T03:42:52.277

SOURCES RELEASE DATE

db:VULHUBid:VHN-405313date:2022-05-03T00:00:00
db:JVNDBid:JVNDB-2022-010592date:2023-08-16T00:00:00
db:CNNVDid:CNNVD-202204-4507date:2022-04-27T00:00:00
db:NVDid:CVE-2022-20760date:2022-05-03T04:15:09.893