<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: FTD 4120 Vulnerability in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/ftd-4120-vulnerability/m-p/3752977#M984541</link>
    <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Apache Remote Web Server is affected by multiple vulnerabilities on the FXOS Version 2.3(1.73)&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;A href="https://bst.cloudapps.cisco.com/bugsearch/bug/CSCvj48872/?rfs=iqvred" target="_self"&gt;CSCvj48872&lt;/A&gt; it is fixed on the&amp;nbsp; version 2.3(1.88) &amp;amp;&amp;nbsp;2.3(1.82)&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Multiple Common Vulnerability and Exposures ID's CVE-2017-15710, CVE-2017-15715, CVE-2018-1283, CVE-2018-1301, CVE-2018-1302, CVE-2018-1303, &lt;BR /&gt;CVE-2018-1312&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;HTH&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Abheesh&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Mon, 26 Nov 2018 18:24:39 GMT</pubDate>
    <dc:creator>Abheesh Kumar</dc:creator>
    <dc:date>2018-11-26T18:24:39Z</dc:date>
    <item>
      <title>FTD 4120 Vulnerability</title>
      <link>https://community.cisco.com/t5/network-security/ftd-4120-vulnerability/m-p/3752938#M984540</link>
      <description>&lt;P&gt;Hello!&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;During a vulnerability scan on my FTD 4120, I was provided with the below vulnerability to resolve. Can you tell me if 4120 has enabled the H2 protocol?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Vulnerability description:&lt;/P&gt;
&lt;P&gt;Apache HTTPD: DoS for HTTP/2 connections by continuous SETTINGS (CVE-2018-11763)&lt;BR /&gt;By sending continous SETTINGS frames of maximum size an ongoing HTTP/2 connection could be kept busy and would never time out. This can be abused for a DoS on the server. This only affect a server that has enabled the h2 protocol.&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 16:30:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ftd-4120-vulnerability/m-p/3752938#M984540</guid>
      <dc:creator>ChristopherO</dc:creator>
      <dc:date>2020-02-21T16:30:18Z</dc:date>
    </item>
    <item>
      <title>Re: FTD 4120 Vulnerability</title>
      <link>https://community.cisco.com/t5/network-security/ftd-4120-vulnerability/m-p/3752977#M984541</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Apache Remote Web Server is affected by multiple vulnerabilities on the FXOS Version 2.3(1.73)&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;A href="https://bst.cloudapps.cisco.com/bugsearch/bug/CSCvj48872/?rfs=iqvred" target="_self"&gt;CSCvj48872&lt;/A&gt; it is fixed on the&amp;nbsp; version 2.3(1.88) &amp;amp;&amp;nbsp;2.3(1.82)&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Multiple Common Vulnerability and Exposures ID's CVE-2017-15710, CVE-2017-15715, CVE-2018-1283, CVE-2018-1301, CVE-2018-1302, CVE-2018-1303, &lt;BR /&gt;CVE-2018-1312&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;HTH&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Abheesh&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 26 Nov 2018 18:24:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ftd-4120-vulnerability/m-p/3752977#M984541</guid>
      <dc:creator>Abheesh Kumar</dc:creator>
      <dc:date>2018-11-26T18:24:39Z</dc:date>
    </item>
    <item>
      <title>Re: FTD 4120 Vulnerability</title>
      <link>https://community.cisco.com/t5/network-security/ftd-4120-vulnerability/m-p/3753012#M984542</link>
      <description>&lt;P&gt;Thanks for the quick response Abheesh,&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The FXOS version installed is 2.3(1.88) and I plan to upgrade to 2.3(1.56) soon.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The Vulnerability has Exposures ID of CVE-2018-11763 listed which i didn't see listed below. If I am running FXOS 2.3(1.88) and the scan still is reporting the vulnerability, what should i do to resolve this, or should it be marked as a false positive?&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks for your help!&lt;/P&gt;
&lt;P&gt;Chris&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 26 Nov 2018 19:40:21 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ftd-4120-vulnerability/m-p/3753012#M984542</guid>
      <dc:creator>ChristopherO</dc:creator>
      <dc:date>2018-11-26T19:40:21Z</dc:date>
    </item>
    <item>
      <title>Re: FTD 4120 Vulnerability</title>
      <link>https://community.cisco.com/t5/network-security/ftd-4120-vulnerability/m-p/3753067#M984543</link>
      <description>Hi,&lt;BR /&gt;Are you planning to downgrade...??? I think its recommended to upgrade to latest version. &lt;BR /&gt;As per the bug CSCvj48872, its fixed on the mentioned releases but in your case as per the vulnerability scan its still affected, my suggestion is to open a ticket with cisco for further more verification/analysis.&lt;BR /&gt;&lt;BR /&gt;HTH&lt;BR /&gt;Abheesh</description>
      <pubDate>Mon, 26 Nov 2018 20:49:50 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ftd-4120-vulnerability/m-p/3753067#M984543</guid>
      <dc:creator>Abheesh Kumar</dc:creator>
      <dc:date>2018-11-26T20:49:50Z</dc:date>
    </item>
  </channel>
</rss>

