[CIVN-2025-0186] Denial of Service Vulnerability in CISCO
—–BEGIN PGP SIGNED MESSAGE—–
Hash: SHA256
Denial of Service Vulnerability in CISCO
Indian – Computer Emergency Response Team (https://www.cert-in.org.in)
Severity Rating: HIGH
Software Affected
Cisco Secure FTD Software
Overview
A vulnerability has been reported in packet inspection functionality of the Snort 3 Detection Engine of Cisco Secure Firewall Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device.
Target Audience:
All IT administrators and individuals responsible for maintaining and updating Cisco Secure Firewall Threat Defense (FTD) Software.
Risk Assessment:
High risk of data manipulation and service disruption.
Impact Assessment:
Potential impact on confidentiality, integrity, and availability of the system.
Description
This vulnerability exists due to incorrect processing of traffic that is inspected by an affected device. An attacker could exploit this vulnerability by sending crafted traffic through the affected device.
Successful exploitation of this vulnerability could allow the attacker to cause the affected device to enter an infinite loop while inspecting traffic, resulting in a DoS condition.
Solution
Apply appropriate updates as mentioned in Cisco Advisory
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ftd-dos-SvKhtjgt
Vendor Information
CISCO
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ftd-dos-SvKhtjgt
References
CISCO
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ftd-dos-SvKhtjgt
CVE Name
CVE-2025-20217
– —
Thanks and Regards,
CERT-In
Incident Response Help Desk
e-mail: incident@cert-in.org.in
Phone: +91-11-22902657
Toll Free Number: 1800-11-4949
Toll Free Fax : 1800-11-6969
Web: http://www.cert-in.org.in
PGP Fingerprint: A768 083E 4475 5725 B81A A379 2156 C0C0 B620 D0B4
PGP Key information:
https://www.cert-in.org.in/s2cMainServlet?pageid=CONTACTUS
Postal address:
Indian Computer Emergency Response Team (CERT-In)
Ministry of Electronics and Information Technology
Government of India
Electronics Niketan
6, C.G.O. Complex
New Delhi-110 003
—–BEGIN PGP SIGNATURE—–
iQIzBAEBCAAdFiEE6r4Iam/Ey0c/KakL3jCgcSdcys8FAmipyzMACgkQ3jCgcSdc
ys/WBg/7B5JzgjSJ8cwVsfQBQqgzkq5W609QmNBrvUo8u7Ka+pVGJZ7Of9ClaW9p
rSroFDwldMBOPcPM8spOkIFYMZADZ4myA4y99Eft+sN7ZbS5vlB22ChBrxUQ9xHa
4WRqTarCmgdjTMoCvSRhtfQ4E0cVRGTh+0HUPpr5jFGHGNmnhnU7NBVps12DJzuQ
GN64c1reh4pdxl4CSFOvZmce6yc1gWuo+420vsfrqXf6V/IdF5po3gecaEne56aS
bfTp06k+ZvVETkny3pVlL3c2AKnuURZhHPcn3IdnSuvWbhRbR7bNpAyusP/3Uv7T
fvflSe4KZFfVcasxxLu6ZMAxEV1wzoL9AVclQHMac0khOIlPwoi2+ZGG++nNEUtS
1A+jE+uFv7kHruOe9SD8AaBH0ZYCCLk8txp2MvMb7VOQDTbLVNVAG3VkIpTzsmya
/4V9+oY8hUYsT053Er2QKg2U6ZD1aUpqJTT4FBe/7crNxHKpqUWI7R8IlGvTl1JM
+1r+kCEUkgHcbAGmCZHaAyShZo8QmlU+kaMTW5GH3beYhgVmcXavrCDElfmuHgs+
VH5erha+8pKKt4GkaMCH2jkPuZwBkCj4pIUPiah8Q8pLt7167PkEfLfLoG1KFI83
cF8D9yESwG4kQy/qbGW6TQP0tVKm4ZKqgRjcqxWiplsrEjQbG4g=
=3XGs
—–END PGP SIGNATURE—–