CVE-2017-6632
CVE-2017-6632 is a high-severity vulnerability in Cisco Firepower Threat Defense with a CVSS 3.x base score of 7.5. It is not currently listed as actively exploited by CISA, and its EPSS exploit-prediction score is low. The underlying weakness is classified as CWE-400.
Key facts
- Severity: High (CVSS 3.x base score 7.5)
- CVSS v2: 7.8
- EPSS exploit prediction: 2% (83rd percentile)
- Actively exploited: Not listed in CISA KEV
- Weakness: CWE-400
- Affected product: Cisco Firepower Threat Defense
- Published:
- Last modified:
Description
A vulnerability in the logging configuration of Secure Sockets Layer (SSL) policies for Cisco FirePOWER System Software 5.3.0 through 6.2.2 could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition due to high consumption of system resources. The vulnerability is due to the logging of certain TCP packets by the affected software. An attacker could exploit this vulnerability by sending a flood of crafted TCP packets to an affected device. A successful exploit could allow the attacker to cause a DoS condition. The success of an exploit is dependent on how an administrator has configured logging for SSL policies for a device. This vulnerability affects Cisco FirePOWER System Software that is configured to log connections by using SSL policy default actions. Cisco Bug IDs: CSCvd07072.
Frequently asked questions
- What is CVE-2017-6632?
- A vulnerability in the logging configuration of Secure Sockets Layer (SSL) policies for Cisco FirePOWER System Software 5.3.0 through 6.2.2 could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition due to high consumption of system resources. The vulnerability is due to the logging of certain TCP packets by the affected software. An attacker could exploit this vulnerability by sending a flood of crafted TCP packets to an affected device. A successful exploit could allow the attacker to cause a DoS condition. The success of an exploit is dependent on how an administrator has configured logging for SSL policies for a device. This vulnerability affects Cisco FirePOWER System Software that is configured to log connections by using SSL policy default actions. Cisco Bug IDs: CSCvd07072.
- How severe is CVE-2017-6632?
- CVE-2017-6632 has a CVSS 3.x base score of 7.5, rated high severity. It is exploitable over network with low attack complexity, requires no privileges and no user interaction. Impact on confidentiality is none, integrity none, and availability high.
- Is CVE-2017-6632 being actively exploited?
- It is not currently listed in CISA's KEV catalog. Its EPSS exploit-prediction score is 2% (83rd percentile), an estimate of the probability of exploitation in the next 30 days.
- What products are affected by CVE-2017-6632?
- CVE-2017-6632 primarily affects Cisco Firepower Threat Defense. In total, 11 product configurations (CPEs) are listed as vulnerable; see the affected-products list for the exact versions.
- How do I fix CVE-2017-6632?
- Review the linked vendor and NVD advisories for patched versions and mitigations, then upgrade or apply the recommended workaround. Given its high severity, prioritise patching exposed systems.
- When was CVE-2017-6632 published?
- CVE-2017-6632 was published on 2017-05-22 and last updated on 2026-08-11.
References
- http://www.securityfocus.com/bid/98523
- https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20170517-fpwr
Affected products (11)
- cpe:2.3:a:cisco:firepower_threat_defense:6.2_base:*:*:*:*:*:*:*
- cpe:2.3:a:cisco:secure_firewall_threat_defense:5.3.0:*:*:*:*:*:*:*
- cpe:2.3:a:cisco:secure_firewall_threat_defense:5.4.0:*:*:*:*:*:*:*
- cpe:2.3:a:cisco:secure_firewall_threat_defense:6.0.0:*:*:*:*:*:*:*
- cpe:2.3:a:cisco:secure_firewall_threat_defense:6.0.1:*:*:*:*:*:*:*
- cpe:2.3:a:cisco:secure_firewall_threat_defense:6.0.1.3:*:*:*:*:*:*:*
- cpe:2.3:a:cisco:secure_firewall_threat_defense:6.1.0:*:*:*:*:*:*:*
- cpe:2.3:a:cisco:secure_firewall_threat_defense:6.1.0.2:*:*:*:*:*:*:*
- cpe:2.3:a:cisco:secure_firewall_threat_defense:6.2.0:*:*:*:*:*:*:*
- cpe:2.3:a:cisco:secure_firewall_threat_defense:6.2.1:*:*:*:*:*:*:*
- cpe:2.3:a:cisco:secure_firewall_threat_defense:6.2.2:*:*:*:*:*:*:*
More vulnerabilities in Cisco Firepower Threat Defense
- CVE-2018-15383 — High (CVSS 7.5): A vulnerability in the cryptographic hardware accelerator driver of Cisco Adaptive Security Appliance (ASA) Software…
- CVE-2018-0296 — High (CVSS 7.5): A vulnerability in the web interface of the Cisco Adaptive Security Appliance (ASA) could allow an unauthenticated,…
- CVE-2020-3457 — Medium (CVSS 6.7): A vulnerability in the CLI of Cisco FXOS Software could allow an authenticated, local attacker to inject arbitrary…
- CVE-2020-3583 — Medium (CVSS 6.1): Multiple vulnerabilities in the web services interface of Cisco Adaptive Security Appliance (ASA) Software and Cisco…
- CVE-2020-3582 — Medium (CVSS 6.1): Multiple vulnerabilities in the web services interface of Cisco Adaptive Security Appliance (ASA) Software and Cisco…
- CVE-2020-3581 — Medium (CVSS 6.1): Multiple vulnerabilities in the web services interface of Cisco Adaptive Security Appliance (ASA) Software and Cisco…
All CVEs affecting Cisco Firepower Threat Defense →
Other CWE-400 (Uncontrolled Resource Consumption) vulnerabilities
- CVE-2026-46775 — Critical (CVSS 9.9): Vulnerability in Oracle REST Data Services (component: Core). Supported versions that are affected are 24.2.0-26.1.0.…
- CVE-2025-61303 — Critical (CVSS 9.8): Hatching Triage Sandbox Windows 10 build 2004 (2025-08-14) and Windows 10 LTSC 2021(2025-08-14) contains a…
- CVE-2025-43193 — Critical (CVSS 9.8): The issue was addressed with improved memory handling. This issue is fixed in macOS Sequoia 15.6, macOS Sonoma 14.7.7,…
- CVE-2025-24269 — Critical (CVSS 9.8): The issue was addressed with improved memory handling. This issue is fixed in macOS Sequoia 15.4. An app may be able to…
- CVE-2025-24264 — Critical (CVSS 9.8): The issue was addressed with improved memory handling. This issue is fixed in Safari 18.4, iOS 18.4 and iPadOS 18.4,…
- CVE-2025-24260 — Critical (CVSS 9.8): The issue was addressed with improved memory handling. This issue is fixed in macOS Sequoia 15.4, macOS Sonoma 14.7.5,…
Browse all CWE-400 (Uncontrolled Resource Consumption) vulnerabilities →