Vulnslist

find the latest Cisco vulnerabilities

Cisco Firepower 9000 Series Firepower 2-Port 100G Double-Width Network Module Queue Wedge Denial of Service Vulnerability

cisco-sa-20190220-firpwr-dos · Medium · Published · Updated

A vulnerability in field-programmable gate array (FPGA) ingress buffer management for the Cisco Firepower 9000 Series with the Cisco Firepower 2-port 100G double-width network module (PID: FPR9K-DNM-2X100G) could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) condition. Manual intervention may be required before a device will resume normal operations. The vulnerability is due to a logic error in the FPGA related to the processing of different types of input packets. An attacker could exploit this vulnerability by being on the adjacent subnet and sending a crafted sequence of input packets to a specific interface on an affected device. A successful exploit could allow the attacker to cause a queue wedge condition on the interface. When a wedge occurs, the affected device will stop processing any additional packets that are received on the wedged interface. There are no workarounds that address this vulnerability. This advisory is available at the following link: https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20190220-firpwr-dos

Cisco advisory · CSAF JSON

Workarounds

There are no workarounds that address this vulnerability.

CVEsCVE-2019-1700
Cisco Bug IDsCSCvn57812
CVSS ScoreBase 6.1
Base 6.1 CVSS:3.0/AV:A/AC:H/PR:N/UI:N/S:C/C:N/I:N/A:H/E:X/RL:X/RC:X
Product Names From Source
Cisco Firepower Extensible Operating System (FXOS)

Related Products

Product CVE Evidence
Firepower Extensible Operating System CVE-2019-1700 Cisco OpenVuln
Cisco Firepower Extensible Operating System (FXOS) CVE-2019-1700 Cisco OpenVuln
Cisco Firepower Extensible Operating System CVE-2019-1700 Cisco OpenVuln
Cisco Firepower 9000 Series CVE-2019-1700 Cisco OpenVuln