CVE-2017-12245 (CNNVD-201710-060)
中文标题:
多款Cisco产品Firepower Threat Defense Software 安全漏洞
英文标题:
A vulnerability in SSL traffic decryption for Cisco Firepower Threat Defense (FTD) Software could al...
漏洞描述
中文描述:
Cisco Appliance (ASA) 5500-X Series Next-Generation Firewalls等都是美国思科(Cisco)公司的防火墙产品。Firepower Threat Defense(FTD)Software是其中的一套入侵防御系统。 多款Cisco产品中的FTD Software 6.1版本和6.2版本的SSL流量加密过程存在拒绝服务漏洞。远程攻击者可通过发送恶意的Secure Sockets Layer (SSL)流量利用该漏洞造成拒绝服务(系统内存耗尽)。以下产品受到影响:Cisco Adaptive Security Appliance (ASA) 5500-X Series Next-Generation Firewalls;Firepower 2100 Series Security Appliances;Firepower 4100 Series Security Appliances;Firepower 9300 Series Security Appliances。
英文描述:
A vulnerability in SSL traffic decryption for Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause depletion of system memory, aka a Firepower Detection Engine SSL Decryption Memory Consumption Denial of Service vulnerability. If this memory leak persists over time, a denial of service (DoS) condition could develop because traffic can cease to be forwarded through the device. The vulnerability is due to an error in how the Firepower Detection Snort Engine handles SSL traffic decryption and notifications to and from the Adaptive Security Appliance (ASA) handler. An attacker could exploit this vulnerability by sending a steady stream of malicious Secure Sockets Layer (SSL) traffic through the device. An exploit could allow the attacker to cause a DoS condition when the device runs low on system memory. This vulnerability affects Cisco Firepower Threat Defense (FTD) Software Releases 6.0.1 and later, running on any of the following Cisco products: Adaptive Security Appliance (ASA) 5500-X Series Next-Generation Firewalls, Firepower 2100 Series Security Appliances, Firepower 4100 Series Security Appliances, Firepower 9300 Series Security Appliances. Cisco Bug IDs: CSCve02069.
CWE类型:
标签:
受影响产品
| 厂商 | 产品 | 版本 | 版本范围 | 平台 | CPE |
|---|---|---|---|---|---|
| cisco | secure_firewall_management_center | 6.0.1 | - | - |
cpe:2.3:a:cisco:secure_firewall_management_center:6.0.1:*:*:*:*:*:*:*
|
| cisco | secure_firewall_management_center | 6.0.1.3 | - | - |
cpe:2.3:a:cisco:secure_firewall_management_center:6.0.1.3:*:*:*:*:*:*:*
|
| cisco | secure_firewall_management_center | 6.1.0 | - | - |
cpe:2.3:a:cisco:secure_firewall_management_center:6.1.0:*:*:*:*:*:*:*
|
| cisco | secure_firewall_management_center | 6.1.0.3 | - | - |
cpe:2.3:a:cisco:secure_firewall_management_center:6.1.0.3:*:*:*:*:*:*:*
|
| cisco | secure_firewall_management_center | 6.1.0.6 | - | - |
cpe:2.3:a:cisco:secure_firewall_management_center:6.1.0.6:*:*:*:*:*:*:*
|
| cisco | secure_firewall_management_center | 6.2.0 | - | - |
cpe:2.3:a:cisco:secure_firewall_management_center:6.2.0:*:*:*:*:*:*:*
|
| cisco | secure_firewall_management_center | 6.2.0.2 | - | - |
cpe:2.3:a:cisco:secure_firewall_management_center:6.2.0.2:*:*:*:*:*:*:*
|
| cisco | secure_firewall_management_center | 6.2.1 | - | - |
cpe:2.3:a:cisco:secure_firewall_management_center:6.2.1:*:*:*:*:*:*:*
|
| cisco | secure_firewall_management_center | 6.2.2 | - | - |
cpe:2.3:a:cisco:secure_firewall_management_center:6.2.2:*:*:*:*:*:*:*
|
解决方案
中文解决方案:
英文解决方案:
临时解决方案:
CVSS评分详情
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H
时间信息
利用信息
数据源详情
| 数据源 | 记录ID | 版本 | 提取时间 |
|---|---|---|---|
| CVE | cve_CVE-2017-12245 |
2025-11-11 15:19:17 | 2025-11-11 07:34:33 |
| NVD | nvd_CVE-2017-12245 |
2025-11-11 14:55:32 | 2025-11-11 07:43:12 |
| CNNVD | cnnvd_CNNVD-201710-060 |
2025-11-11 15:09:54 | 2025-11-11 07:53:19 |
版本与语言
安全公告
变更历史
查看详细变更
- vulnerability_type: 未提取 -> 资源管理错误
- cnnvd_id: 未提取 -> CNNVD-201710-060
- data_sources: ['cve', 'nvd'] -> ['cnnvd', 'cve', 'nvd']
查看详细变更
- severity: SeverityLevel.MEDIUM -> SeverityLevel.HIGH
- cvss_score: 未提取 -> 8.6
- cvss_vector: NOT_EXTRACTED -> CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H
- cvss_version: NOT_EXTRACTED -> 3.0
- affected_products_count: 0 -> 9
- data_sources: ['cve'] -> ['cve', 'nvd']