CVE-2023-20244
A vulnerability in the internal packet processing of Cisco Firepower Threat Defense (FTD) Software for Cisco Firepower 2100 Series Firewalls could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to improper handling of certain packets when they are sent to the inspection engine. An attacker could exploit this vulnerability by sending a series of crafted packets to an affected device. A successful exploit could allow the attacker to deplete all 9,472 byte blocks on the device, resulting in traffic loss across the device or an unexpected reload of the device. If the device does not reload on its own, a manual reload of the device would be required to recover from this state.
Scoring
- Severity
- HIGH
- CVSS base score
- 8.6
- CVSS vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H
- EPSS probability
- 0.17%
- CWE
- CWE-771
- Published
- 2023-11-01
- Last modified
- 2026-03-13
Affected products
- Cisco Cisco Firepower Threat Defense Software
- Cisco Cisco Firepower Threat Defense Software
- Cisco Cisco Firepower Threat Defense Software
- Cisco Cisco Firepower Threat Defense Software
- Cisco Cisco Firepower Threat Defense Software
- Cisco Cisco Firepower Threat Defense Software
- Cisco Cisco Firepower Threat Defense Software
- Cisco Cisco Firepower Threat Defense Software
Weakness type
Related vulnerabilities
- CVE-2026-3039 — BIND 9 server memory exhaustion during GSS-API TKEY negotiation
- CVE-2026-20004 — A vulnerability in the TLS library of Cisco IOS XE Software could allow an unauthenticated,...
- CVE-2025-21090 — Missing reference to active allocated resource for some Intel(R) Xeon(R) processors may allow an...
- CVE-2024-56343 — IBM Verify Identity Access Digital Credentials denial of service
- CVE-2021-34720 — Cisco IOS XR Software IP Service Level Agreements and Two-Way Active Measurement Protocol Denial of Service Vulnerability