Not a U.S. government website. NDD is an independent vulnerability database by Volerion and is not affiliated with or endorsed by NIST or NVD.
VOLERION
Volerion Security Research

NOT DEFERRED DATABASE

VULNERABILITIES

CVE-2019-1700 Details

Description

A vulnerability in field-programmable gate array (FPGA) ingress buffer management for the Cisco Firepower 9000 Series with the Cisco Firepower 2-port 100G double-width network module (PID: FPR9K-DNM-2X100G) could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) condition. Manual intervention may be required before a device will resume normal operations. The vulnerability is due to a logic error in the FPGA related to the processing of different types of input packets. An attacker could exploit this vulnerability by being on the adjacent subnet and sending a crafted sequence of input packets to a specific interface on an affected device. A successful exploit could allow the attacker to cause a queue wedge condition on the interface. When a wedge occurs, the affected device will stop processing any additional packets that are received on the wedged interface. Version 2.2 is affected.

Metrics

References to Advisories, Solutions, and Tools

By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.

Weakness Enumeration

CWE-IDCWE NameSource
CWE-399Resource Management Errors[email protected]
CWE-399Resource Management Errors[email protected]

Affected Products

ProductVersions
cisco firepower 9000 firmware
2.2(200.8)

CPE

  • cpe:2.3:o:cisco:firepower_9000_firmware:2.2(200.8):*:*:*:*:*:*:*

Remediation

  • No remediation found in references.
cisco firepower 9000
All versions

CPE

  • cpe:2.3:h:cisco:firepower_9000:-:*:*:*:*:*:*:*

Remediation

  • No remediation found in references.

Change History

7 change records found show changes


QUICK INFO

CVE Dictionary Entry:
CVE-2019-1700
NVD Published Date:
Feb 21, 2019
NVD Last Modified:
Jun 17, 2026
Source:
[email protected]
CVE-2019-1700 Details - Not Deferred