Cisco Secure Firewall Threat D... ノート

Cisco Secure Firewall Threat Defense Software Snort 2 SSL/TLS Denial of Service Vulnerability

Cisco Secure Firewall Threat Defense (FTD) Software の Snort 2 Detection Engine における SSL/TLS 証明書解析の脆弱性により、認証されていないリモートの攻撃者が Snort 2 Detection Engine を再起動させることが可能になる場合があります。この脆弱性は、SSL 証明書の検証が不完全であることに起因します。攻撃者は、Snort 2 によって解析されるように細工された SSL 接続セットアップ要求を送信することで、この脆弱性を悪用する可能性があります。悪用に成功すると、攻撃者は Snort 2 Detection Engine を予期せず再起動させ、サービス拒否 (DoS) 状態を引き起こす可能性があります。Cisco は、この脆弱性に対処するソフトウェアアップデートをリリースしました。この脆弱性に対処する回避策はありません。このアドバイザリは、次のリンクで入手できます: https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ftd-snort2-ssldos-Mw7WYX9cこのアドバイザリは、一連のアドバイザリの一部です。アドバイザリの完全なリストとそれらへのリンクについては、Cisco Advance Notification for Publication of September 16, 2026, Security Advisories を参照してください。さらに、Cisco Secure Firewall 製品の改善と修正に関する詳細なドキュメントについては、Cisco Secure Firewall Adaptive Security Appliance Software, Secure Firewall Threat Defense Software, and Secure Firewall Management Center Software Hardening Release: September 2026 を参照してください。セキュリティ影響度評価: 中CVE: CVE-2026-20290