CVE-2020-27124 is a denial-of-service vulnerability in the SSL/TLS handler of Cisco Adaptive Security Appliance (ASA) Software. An unauthenticated, remote attacker can exploit improper error handling in established SSL/TLS connections by sending a malicious message, causing the device to reload unexpectedly. This vulnerability has a high CVSS score of 8.6, indicating a severe impact on availability with low attack complexity and no user interaction required. While Cisco has released patches, there are no known workarounds, and there is currently no public exploit code or evidence of active exploitation, nor significant community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
9.13.1.12CPE matchmatch criteria | cpe:2.3:o:cisco:adaptive_security_appliance_software:9.13.1.12:*:*:*:*:*:*:* | ||
9.13.1.13CPE matchmatch criteria | cpe:2.3:o:cisco:adaptive_security_appliance_software:9.13.1.13:*:*:*:*:*:*:* | ||
9.14.1.10CPE matchmatch criteria | cpe:2.3:o:cisco:adaptive_security_appliance_software:9.14.1.10:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.