Cisco Secure Firewall Adaptive Security Appliance and Secure Firewall Threat Defense Software Access Control Rules Bypass Vulnerability
TL;DR 📌
A medium severity vulnerability has been identified in Cisco Secure Firewall Adaptive Security Appliance (ASA) and Secure Firewall Threat Defense (FTD) Software, allowing unauthenticated remote attackers to bypass access control rules for loopback interfaces. No workarounds are available, and software updates are necessary to mitigate the risk.
What happened 🕵️♂️
Cisco has disclosed a vulnerability in the access control rules implementation for loopback interfaces in its Secure Firewall ASA and FTD Software. This flaw could enable an unauthenticated remote attacker to send traffic that should be blocked to a loopback interface, effectively bypassing configured access control rules. The vulnerability arises from improper enforcement of these rules, posing a potential risk to network security.
Affected products 🖥️
The vulnerability affects Cisco Secure Firewall ASA and Secure Firewall FTD Software running vulnerable releases that have at least one loopback interface configured and enabled. Loopback interfaces are not configured by default, so devices without them are not at risk.
Fixed software 🔧
Upgrade to the first fixed release in your train (or later):
| Release / Product | First Fixed Release | Notes |
|---|---|---|
| 1.0 | Initial public release. | |
| Cisco Secure Firewall ASA | 9.16.2.11 | |
| Cisco Secure FTD Software | 6.6.7 | |
| Cisco Secure FMC | 6.6.7 |
Workarounds 🧯
There are no workarounds available to mitigate this vulnerability.
Risk in context 🎯
The highest CVSS score for this vulnerability is 5.3, categorizing it as medium severity. While the risk is not critical, the potential for unauthorized access to loopback interfaces could lead to further exploitation if not addressed. Organizations should prioritize applying the necessary software updates to protect their network infrastructure.
Fast facts ⚡
- Vulnerability: Access Control Rules Bypass
- CVSS Score: 5.3 (Medium)
- Exploitability: Unauthenticated remote access possible
- Workarounds: None available
- Impact: Potential unauthorized access to loopback interfaces
For leadership 🧭
Executive summary. Firewalls running Cisco ASA or FTD software with a loopback interface enabled may pass traffic to that interface that access control rules are meant to block, without requiring any credentials. There is no workaround, so remediation depends entirely on scheduling the software upgrade; treat it as routine patching rather than an emergency given the medium severity rating.
Why it matters:
- The bypass only applies to devices with at least one loopback interface configured and enabled — check your ASA/FTD configs to know if this affects you at all.
- An unauthenticated remote attacker can send traffic to the loopback interface that configured access control rules should have dropped, undermining the filtering policy on that interface.
- No workaround exists, so mitigation is limited to upgrading ASA to 9.16.2.11 or later, or FTD/FMC to 6.6.7 or later.
- Affects core perimeter firewall software (ASA and FTD), meaning any bypass has direct implications for whatever traffic policy the loopback interface was meant to enforce.
Now / Next / Later:
- Now: Audit your Cisco ASA and FTD deployments to identify which ones have a loopback interface configured and enabled — those are the only devices exposed.
- Next: Schedule an upgrade of affected ASA devices to 9.16.2.11 (or later) and FTD/FMC to 6.6.7 (or later) in the next maintenance window, since no interim workaround is available.
- Later: Add loopback interface configuration to your standard firewall hardening review so any future use of loopback interfaces is checked against current fixed releases before deployment.