CVE-2020-3189 is a high-severity memory leak vulnerability affecting Cisco Firepower Threat Defense (FTD) Software. An unauthenticated, remote attacker can exploit this flaw by repeatedly creating and deleting VPN connections, causing the system to slowly deplete memory during VPN System Logging events. This can lead to unexpected system behaviors or a denial-of-service (DoS) condition due to system memory exhaustion. The vulnerability has a CVSS score of 8.6, indicating a high impact, and is easily exploitable with low attack complexity. While there is no known active exploitation or public exploit code, the vulnerability has garnered some community discussion and media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
6.2.3.12CPE matchmatch criteria | cpe:2.3:a:cisco:firepower_threat_defense:6.2.3.12:*:*:*:*:*:*:* | ||
6.2.3.13CPE matchmatch criteria | cpe:2.3:a:cisco:firepower_threat_defense:6.2.3.13:*:*:*:*:*:*:* | ||
6.2.3.14CPE matchmatch criteria | cpe:2.3:a:cisco:firepower_threat_defense:6.2.3.14:*:*:*:*:*:*:* | ||
6.2.3.15CPE matchmatch criteria | cpe:2.3:a:cisco:firepower_threat_defense:6.2.3.15:*:*:*:*:*:*:* | ||
9.9\(2\)CPE matchmatch criteria | cpe:2.3:o:cisco:asa_5505_firmware:9.9\(2\):*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.