Cisco Secure Firewall Adaptive Security Appliance and Secure Firewall Threat Defense Software DHCP Denial of Service Vulnerability

🚨 SEVERITY: MEDIUM — CVSS 4.3 Security Advisory

TL;DR 📌

A medium-severity vulnerability has been identified in the DHCP client functionality of Cisco Secure Firewall ASA and FTD Software. This flaw could allow an unauthenticated adjacent attacker to exhaust device memory, leading to a Denial of Service (DoS) condition. Cisco has released software updates to mitigate this risk, but no workarounds are available.

What happened 🕵️‍♂️

A vulnerability in the DHCP client functionality of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software has been discovered. This issue arises from improper validation of incoming DHCP packets, allowing an attacker to send crafted DHCPv4 packets to the device. If exploited, the attacker could exhaust the device’s available memory, resulting in service unavailability and requiring a manual reboot to restore functionality.

Affected products 🖥️

The vulnerability affects devices with the DHCP client feature enabled running vulnerable releases of Cisco Secure Firewall ASA Software and Secure FTD Software. Notably, on Cisco Secure FTD Software, only data interfaces are impacted, while management interfaces remain unaffected.

Fixed software 🔧

Upgrade to the first fixed release in your train (or later):

Release / Product First Fixed Release Notes
1.0 Initial public release.

Workarounds 🧯

There are no workarounds available to mitigate this vulnerability.

Risk in context 🎯

With a CVSS score of 4.3, this vulnerability is classified as medium severity. The risk is primarily driven by the potential for an unauthenticated attacker to exploit the vulnerability from an adjacent network, leading to service disruption. Organizations should prioritize applying the available updates to mitigate the risk of exploitation.

Fast facts ⚡

  • Vulnerability: DHCP Denial of Service
  • CVSS Score: 4.3 (Medium)
  • Impact: Denial of Service (DoS)
  • Exploitation: Requires adjacent network access, no authentication needed.
  • Workarounds: None available.
  • Fixed Software: Updates released, specific versions not listed.

For leadership 🧭

Executive summary. Firewalls running affected Cisco ASA or FTD software with DHCP client enabled can be knocked offline by a nearby attacker sending malformed DHCPv4 traffic, and recovery requires someone to physically or remotely reboot the device. There is no workaround, so this should be scheduled into the next available maintenance window rather than left indefinitely.

Why it matters:

  • The attack targets the DHCP client on ASA and FTD data interfaces, meaning any device configured to obtain an address via DHCP is exposed to crafted DHCPv4 packets from the local network segment.
  • No authentication is required, only adjacency to the affected interface, which lowers the bar for anyone already positioned on the same network segment.
  • Exploitation exhausts device memory and causes a denial of service that does not clear itself; a manual reboot is needed to restore the firewall’s normal operation.
  • There are no workarounds, so mitigation depends entirely on applying Cisco’s fixed software rather than configuration changes.

Now / Next / Later:

  • Now: Identify which ASA and FTD devices have the DHCP client feature enabled on their data interfaces and confirm their current software release against Cisco’s fixed versions.
  • Next: Schedule and apply the Cisco-provided software update to affected ASA and FTD devices in the next maintenance window, since no interim workaround exists.
  • Later: Review whether DHCP client functionality is actually needed on firewall data interfaces and disable it where static addressing would suffice, reducing this exposure path for future flaws.