High severity7.7NVD Advisory· Published Nov 15, 2022· Updated Jun 17, 2026
CVE-2022-20927
CVE-2022-20927
Description
A vulnerability in the SSL/TLS client of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an authenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to improper memory management when a device initiates SSL/TLS connections. An attacker could exploit this vulnerability by ensuring that the device will connect to an SSL/TLS server that is using specific encryption parameters. A successful exploit could allow the attacker to cause the affected device to unexpectedly reload, resulting in a DoS condition.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
5(expand)+ 1 more
- (no CPE)
- (no CPE)range: 6.6.0
- Range: 9.14.1
- Range: N/A
Patches
Vulnerability mechanics
References
1News mentions
0No linked articles in our index yet.