Not a U.S. government website. NDD is an independent vulnerability database by Volerion and is not affiliated with or endorsed by NIST or NVD.
VOLERION
Volerion Security Research

NOT DEFERRED DATABASE

VULNERABILITIES

CVE-2022-20946 Details

Description

A vulnerability in the generic routing encapsulation (GRE) tunnel decapsulation feature of Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to a memory handling error that occurs when GRE traffic is processed. An attacker could exploit this vulnerability by sending a crafted GRE payload through an affected device. A successful exploit could allow the attacker to cause the device to restart, resulting in a DoS condition. https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ftd-gre-dos-hmedHQPM ["https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ftd-gre-dos-hmedHQPM"] This advisory is part of the November 2022 release of the Cisco ASA, FTD, and FMC Security Advisory Bundled publication.

Metrics

References to Advisories, Solutions, and Tools

By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.

Weakness Enumeration

CWE-IDCWE NameSource
CWE-787Out-of-bounds Write[email protected]
CWE-122Heap-based Buffer Overflow[email protected]

Affected Products

ProductVersions
cisco secure firewall threat defense
>= 6.3.0, <= 6.3.0.5
>= 6.4.0, <= 6.4.0.15
>= 6.5.0, <= 6.5.0.5
>= 6.6.0, <= 6.6.5.2
>= 6.7.0, <= 6.7.0.3

CPE

  • cpe:2.3:a:cisco:secure_firewall_threat_defense:*:*:*:*:*:*:*:*
  • cpe:2.3:a:cisco:secure_firewall_threat_defense:7.1.0.0:*:*:*:*:*:*:*
  • cpe:2.3:a:cisco:secure_firewall_threat_defense:7.1.0.1:*:*:*:*:*:*:*
  • cpe:2.3:a:cisco:secure_firewall_threat_defense:7.1.0.2:*:*:*:*:*:*:*

Remediation

  • No remediation found in references.

Change History

15 change records found show changes


QUICK INFO

CVE Dictionary Entry:
CVE-2022-20946
NVD Published Date:
Nov 15, 2022
NVD Last Modified:
Aug 11, 2026
Source:
[email protected]
CVE-2022-20946 Details - Not Deferred