SB2020102718 - Denial of service in Cisco Adaptive Security Appliance Software and Firepower Threat Defense Software
Published: October 27, 2020
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Arbitrary file upload (CVE-ID: CVE-2020-3436)
The vulnerability allows a remote attacker to compromise vulnerable system.
The vulnerability exists due to the affected software does not efficiently handle the writing of large files to specific folders on the local file system. A remote attacker can upload a malicious file and cause a denial of service (DoS) condition on the target system.
Remediation
Install update from vendor's website.