CVE-2020-3555: Cisco Adaptive Security Appliance
High severity, CVSS 7.5. EPSS: 1.7% chance of exploitation in the next 30 days.
A vulnerability in the SIP inspection process of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause a crash and reload of an affected device, resulting in a denial of service (DoS) condition. The vulnerability is due to a watchdog timeout and crash during the cleanup of threads that are associated with a SIP connection that is being deleted from the connection list. An attacker could exploit this vulnerability by sending a high rate of crafted SIP traffic through an affected device. A successful exploit could allow the attacker to cause a watchdog timeout and crash, resulting in a crash and reload of the affected device.
Affected products
- Cisco Adaptive Security Appliance: before 9.6.4.43 (fixed in 9.6.4.43)
- Cisco Adaptive Security Appliance Software: from 9.7.0, before 9.8.4.24 (fixed in 9.8.4.24); from 9.9.0, before 9.9.2.80 (fixed in 9.9.2.80); from 9.10.0, before 9.10.1.43 (fixed in 9.10.1.43); from 9.12.0, before 9.12.4.2 (fixed in 9.12.4.2); from 9.13.0, before 9.13.1.13 (fixed in 9.13.1.13); from 9.14.0, before 9.14.1.19 (fixed in 9.14.1.19)
- Cisco Secure Firewall Threat Defense: up to and including 6.2.2; from 6.3.0, before 6.3.0.6 (fixed in 6.3.0.6); from 6.4.0, before 6.4.0.10 (fixed in 6.4.0.10); from 6.5.0, before 6.5.0.5 (fixed in 6.5.0.5); version 6.6.0 only
Published 2020-10-21. Last modified 2026-08-11.