Cisco 安全防火墙威胁防御(FTD)软件中 TLS 1.3 实现存在一个漏洞,未认证的远程攻击者可借此使受影响的设备意外重新加载,从而导致拒绝服务(DoS)状况。 该漏洞源于 TLS 1.3 连接过程中的缓冲区管理不当。攻击者可通过在启用了 TLS 1.3 的监听套接字上向受影响系统发送构造的 TLS 1.3 数据包来利用此漏洞。若利用成功,可导致 LINA 进程崩溃,进而触发设备重新加载。该重新加载可能发生在连接认证之前或之后。 注意:TLS 1.3 连接同时包括数据流量和用户管理流量。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Cisco | Cisco Secure Firewall Threat Defense (FTD) Software | 7.0.0 |
affected |
7.0.0.1 |
affected | ||
7.0.1 |
affected | ||
7.0.1.1 |
affected | ||
7.0.2 |
affected | ||
7.2.0 |
affected | ||
7.0.2.1 |
affected | ||
7.0.3 |
affected | ||
| … +50 more rows | |||
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Cisco | Cisco Secure Firewall Threat Defense (FTD) Software | 7.0.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-20192 | 10.0 CRITICAL | Cisco Identity Services Engine Hardening Release - Access Control Vulnerabilities |
| CVE-2026-76460 | 10.0 CRITICAL | Cisco Identity Services Engine Authentication Bypass Vulnerability |
| CVE-2026-76423 | 10.0 CRITICAL | Cisco ISE API Authentication Bypass Vulnerability |
| CVE-2026-20130 | 10.0 CRITICAL | Cisco Identity Services Engine Hardening Release - Improper Neutralization Vulnerabilities |
| CVE-2026-20332 | 9.9 CRITICAL | Cisco Secure Adaptive Security Appliance Software, Secure Firewall Threat Defense Software |
| CVE-2026-20307 | 9.9 CRITICAL | Cisco Identity Services Engine Remote Code Execution Vulnerability |
| CVE-2026-20234 | 9.9 CRITICAL | Cisco Identity Services Engine Hardening Release - Insuffiencently Protected Credential Vu |
| CVE-2026-20324 | 9.9 CRITICAL | Cisco Secure Firewall Management Center sftunnel Root Arbitrary Code Exectution Vulnerabil |
| CVE-2026-20325 | 9.9 CRITICAL | Cisco Nexus Dashboard Software Security Hardening Release September 2026 - Improper Neutra |
| CVE-2026-20329 | 9.9 CRITICAL | Cisco Secure Adaptive Security Appliance Software, Secure Firewall Threat Defense Software |
| CVE-2026-20322 | 9.9 CRITICAL | Cisco Nexus Dashboard Software Security Hardening Release September 2026 - Improper Access |
| CVE-2026-20330 | 9.9 CRITICAL | Cisco Secure Adaptive Security Appliance Software, Secure Firewall Threat Defense Software |
| CVE-2026-20242 | 9.8 CRITICAL | Cisco Secure Firewall Management Center Software Java Deserialization Remote Code Executio |
| CVE-2026-20326 | 9.8 CRITICAL | Cisco Nexus Dashboard Software Security Hardening Release September 2026 - Missing Authent |
| CVE-2026-20331 | 9.6 CRITICAL | Cisco Secure Adaptive Security Appliance Software, Secure Firewall Threat Defense Software |
| CVE-2026-20306 | 9.1 CRITICAL | Cisco Identity Services Engine Command Injection Vulnerability |
| CVE-2026-20211 | 9.1 CRITICAL | Cisco Identity Services Engine Remote Code Execution Vulnerability |
| CVE-2026-20341 | 9.1 CRITICAL | Cisco Secure Firewall Management Center Software sftunnel Deserialization Root Command Exe |
| CVE-2026-20176 | 9.1 CRITICAL | Cisco Identity Services Engine Remote Code Execution Vulnerability |
| CVE-2026-20284 | 9.1 CRITICAL | Cisco Identity Search Engine SXP REST API SQL Injection Vulnerability |
Showing top 20 of 79 CVEs. View all on vendor page → →
No comments yet