
Cloud Vulnerability DB
A community-led vulnerabilities database
A vulnerability (CVE-2020-3196) was identified in the Secure Sockets Layer (SSL)/Transport Layer Security (TLS) handler of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software. The vulnerability stems from improper resource management for inbound SSL/TLS connections, which could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition (CVE Mitre).
The vulnerability is caused by improper resource management for inbound SSL/TLS connections. When exploited, it can lead to memory exhaustion on the affected device. The issue specifically affects the SSL/TLS handler component of the system, impacting how the device manages and processes secure connections (CVE Mitre).
A successful exploitation of this vulnerability could allow an attacker to exhaust the memory on the affected device, causing it to stop accepting new SSL/TLS connections. This results in a denial of service (DoS) condition for services that process SSL/TLS traffic. Manual intervention is required to recover an affected device (CVE Mitre).
An unauthenticated, remote attacker could exploit this vulnerability by establishing multiple SSL/TLS connections with specific conditions to the affected device. The attack requires no authentication, making it particularly concerning from a security perspective (CVE Mitre).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."