Executive Risk Summary
"A vulnerability in the TLS processing feature of Cisco Firepower Threat Defense Software could allow an unauthenticated, remote attacker to cause a denial of service condition on an affected device. The vulnerability is due to an issue that occurs when TLS traffic is processed, and an attacker could exploit this by sending certain TLS traffic over IPv4 through an affected device."
Operational Audit Arsenal
Target Type Firmware Image
Target Asset Cisco Firepower Threat Defense Software
Standard Path Global Firmware
Manual Verification Required
This is a non-Windows asset (Cisco). Use the target asset details and official path provided above to verify your current version against the official vendor advisories listed below.
Patch Impact Forecast
Reboot Required Likely
High
Internal Work Notes
CVE-2024-20339: Unauthenticated remote attacker could cause a denial of service condition on Cisco Firepower Threat Defense Software, requiring immediate patching and reboot.
Technical Intelligence & Operational Utilities • Delivered Weekly
Intelligence Sources
Official Advisoryhttps://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-fmc-xss-M446vbEO
Official Advisoryhttps://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ftd-tls-dos-QXYE5Ufy
Official Advisoryhttps://sec.cloudapps.cisco.com/security/center/viewErp.x?alertId=ERP-75300
Related Cisco Threats
Data compiled from NVD, MSRC, and CISA KEV Catalog. Intelligence synthesized via AI. Scripts provided for diagnostic purposes under MIT License.