CVE-2020-3191 is a high-severity denial-of-service vulnerability affecting Cisco Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD) Software. It stems from improper length validation in IPv6 DNS packet processing, allowing an unauthenticated, remote attacker to cause a device reload by sending a crafted DNS query over IPv6. The vulnerability has a CVSS score of 8.6, indicating a high impact with no user interaction required. While no public exploit code or active exploitation is confirmed, it has garnered some community discussion and media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 6.2.3, < 6.2.3.16CPE matchmatch criteria | cpe:2.3:a:cisco:firepower_threat_defense:*:*:*:*:*:*:*:* | ||
>= 6.3.0, < 6.3.0.6CPE matchmatch criteria | cpe:2.3:a:cisco:firepower_threat_defense:*:*:*:*:*:*:*:* | ||
>= 6.4.0, < 6.4.0.6CPE matchmatch criteria | cpe:2.3:a:cisco:firepower_threat_defense:*:*:*:*:*:*:*:* | ||
9.4\(1\)CPE matchmatch criteria | cpe:2.3:o:cisco:asa_5505_firmware:9.4\(1\):*:*:*:*:*:*:* | ||
96.4\(0.42\)CPE matchmatch criteria | cpe:2.3:o:cisco:asa_5505_firmware:96.4\(0.42\):*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.