Cisco Secure Firewall Adaptive Security Appliance and Secure Firewall Threat Defense Software Authenticated Command Injection Vulnerabilities

🚨 SEVERITY: MEDIUM — CVSS 6.0 Security Advisory

TL;DR 📌

Cisco has identified multiple authenticated command injection vulnerabilities in the Secure Firewall Adaptive Security Appliance (ASA) and Secure Firewall Threat Defense (FTD) Software. These vulnerabilities could allow an authenticated local attacker to execute arbitrary commands on the underlying operating system with root-level privileges. The highest CVSS score is 6.0, indicating a medium severity risk. Software updates are available to address these vulnerabilities, but there are no workarounds.

What happened 🕵️‍♂️

Cisco has released an advisory detailing vulnerabilities in the Secure Firewall ASA and FTD Software. These vulnerabilities stem from insufficient input validation of commands supplied by users. An attacker with valid administrative credentials could exploit these vulnerabilities to execute commands on the operating system as root. Cisco has confirmed that there are no known public exploits or malicious use of these vulnerabilities at this time.

Affected products 🖥️

The vulnerabilities affect:

  • Cisco Secure Firewall Adaptive Security Appliance (ASA) Software
  • Cisco Secure Firewall Threat Defense (FTD) Software

No products other than those listed are known to be affected.

Fixed software 🔧

Upgrade to the first fixed release in your train (or later):

Release / Product First Fixed Release Notes
1.0 Initial public release.

Workarounds 🧯

There are no workarounds available to mitigate these vulnerabilities.

Risk in context 🎯

With a CVSS score of 6.0, the risk is categorized as Medium. The vulnerabilities require authenticated access, limiting exposure primarily to local attackers with administrative credentials. However, the potential for command execution at the root level poses a significant risk if exploited.

Fast facts ⚡

  • Vulnerabilities: Authenticated command injection
  • CVSS Score: 6.0 (Medium)
  • Impact: Local authenticated attackers can execute arbitrary commands
  • Workarounds: None available
  • Status: Software updates released

For leadership 🧭

Executive summary. Anyone holding administrative credentials on affected ASA or FTD firewalls could escalate to root-level control of the device’s operating system. There is no workaround, so the fix depends on patching, though the requirement for existing admin access keeps the immediate risk at medium.

Why it matters:

  • Exploitation requires only valid administrative credentials on the ASA or FTD appliance, not a separate exploit chain, so any compromised or misused admin account becomes a path to root.
  • Root-level access on a firewall’s underlying OS means an attacker could alter security policy, inspect or redirect traffic, or persist changes beneath the normal management interface.
  • No workaround exists, so exposure remains until the fixed software is installed, making patch timing the only real control.
  • Because ASA and FTD sit at the network perimeter, root compromise here has a broader blast radius than a typical server, affecting everything the firewall protects.

Now / Next / Later:

  • Now: Identify every ASA and FTD appliance in your estate and check its current software version against the advisory’s fixed releases.
  • Next: Schedule and apply the vendor-fixed software update to affected ASA and FTD devices in the next available change window, prioritising those with broad or shared administrative access.
  • Later: Tighten and audit administrative access to firewall management, including reducing the number of accounts with admin privileges and reviewing credential-sharing practices.