← Vulnerability feed

Vulnerability record · CVE-2019-1700 · published 21 February 2019

CVE-2019-1700: Cisco firepower 9000 firmware vulnerability

Cisco · Firepower 9000 Firmware

A vulnerability in field-programmable gate array (FPGA) ingress buffer management for the Cisco Firepower 9000 Series with the Cisco Firepower 2-port 100G double-width network module (PID: FPR9K-DNM-2X100G) could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) condition. Manual intervention may be required before a device will resume normal operations. The vulnerability is due to a logic error in the FPGA related to the processing of different types of input packets. An attacker could exploit this vulnerability by being on the adjacent subnet and sending a crafted sequence of input packets to a specific interface on an affected device. A successful exploit could allow the attacker to cause a queue wedge condition on the interface. When a wedge occurs, the affected device will stop processing any additional packets that are received on the wedged interface. Version 2.2 is affected.

6.1 CVSS 3.0 Medium EPSS 0.50% · top 59.6% CWE-399 · CWE-399
6.1CVSS 3.0 base score, v2 5.7
0.50%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
4References
17 Jun 2026Last modified by NVD

Description

A vulnerability in field-programmable gate array (FPGA) ingress buffer management for the Cisco Firepower 9000 Series with the Cisco Firepower 2-port 100G double-width network module (PID: FPR9K-DNM-2X100G) could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) condition. Manual intervention may be required before a device will resume normal operations. The vulnerability is due to a logic error in the FPGA related to the processing of different types of input packets. An attacker could exploit this vulnerability by being on the adjacent subnet and sending a crafted sequence of input packets to a specific interface on an affected device. A successful exploit could allow the attacker to cause a queue wedge condition on the interface. When a wedge occurs, the affected device will stop processing any additional packets that are received on the wedged interface. Version 2.2 is affected.

CVSS:3.0/AV:A/AC:H/PR:N/UI:N/S:C/C:N/I:N/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2019-1700 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2018-0304Cisco nexus 7000 firmware improper input validation vulnerabilityA vulnerability in the Cisco Fabric Services component of Cisco FXOS Software and Cisco NX-OS Software could allow an unauthenticated, remote attacke…EPSS 8.6%9.8CVE-2018-0308Cisco nexus 7000 firmware improper input validation vulnerabilityA vulnerability in the Cisco Fabric Services component of Cisco FXOS Software and Cisco NX-OS Software could allow an unauthenticated, remote attacke…EPSS 5.6%9.8CVE-2018-0312Cisco nexus 7000 firmware improper input validation vulnerabilityA vulnerability in the Cisco Fabric Services component of Cisco FXOS Software and Cisco NX-OS Software could allow an unauthenticated, remote attacke…EPSS 5.6%9.8CVE-2018-0314Cisco nexus 7000 firmware improper input validation vulnerabilityA vulnerability in the Cisco Fabric Services (CFS) component of Cisco FXOS Software and Cisco NX-OS Software could allow an unauthenticated, remote a…EPSS 5.9%8.6CVE-2018-0305Cisco nexus 7000 firmware null pointer dereference vulnerabilityA vulnerability in the Cisco Fabric Services component of Cisco FXOS Software and Cisco NX-OS Software could allow an unauthenticated, remote attacke…EPSS 2.3%6.7CVE-2019-1649Cisco asa 5500 firmware improper access control vulnerabilityA vulnerability in the logic that handles access control to one of the hardware components in Cisco's proprietary Secure Boot implementation could al…EPSS 0.61%8.8CVE-2010-0806Microsoft Internet Explorer Peer Objects use-after-free allows remote code executionInternet Explorer 6, 6 SP1 and 7 contain a use-after-free in the Peer Objects component (iepeers.dll), where an object is accessed after deletion, le…KEVEPSS 82%analysed5.9CVE-2018-0180Cisco IOS Login Block feature denial-of-service via crafted login attemptsMultiple flaws in the Login Enhancements (Login Block) feature of Cisco IOS Software let an unauthenticated remote attacker trigger a reload of the d…KEVEPSS 4.9%analysed

Source: NIST National Vulnerability Database (record CVE-2019-1700), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.