Cisco Secure Firewall Adaptive Security Appliance and Secure Firewall Threat Defense Software for Firepower 2100 Series IPv6 over IPsec Denial of Service Vulnerability

🚨 SEVERITY: HIGH — CVSS 8.6 Security Advisory

TL;DR 📌

A denial of service (DoS) vulnerability has been identified in the Cisco Secure Firewall Adaptive Security Appliance (ASA) and Secure Firewall Threat Defense (FTD) Software for the Firepower 2100 Series. This vulnerability allows unauthenticated remote attackers to cause a device reload by sending specially crafted IPv6 packets over an IPsec VPN connection. Cisco has released software updates to address this issue, but there are no workarounds available.

What happened 🕵️‍♂️

A vulnerability has been discovered in the RADIUS proxy feature of the IPsec VPN functionality within Cisco Secure Firewall ASA and FTD Software. This flaw arises from improper processing of IPv6 packets, enabling an unauthenticated remote attacker to trigger a denial of service condition by sending crafted packets. A successful exploit can lead to the affected device reloading, resulting in service disruption.

Affected products 🖥️

The vulnerability affects Cisco Firepower 2100 Series Firewalls running vulnerable versions of Cisco Secure Firewall ASA Software or Secure FTD Software under the following conditions:

  • IPsec VPN with IKEv1 or IKEv2 is enabled.
  • IPv6 is enabled on the interface receiving RADIUS traffic.
  • An access control list (ACL) is configured to permit IP traffic.

Fixed software 🔧

Upgrade to the first fixed release in your train (or later):

Release / Product First Fixed Release Notes
1.0 Initial public release.

Workarounds 🧯

There are no workarounds available to mitigate this vulnerability.

Risk in context 🎯

With a CVSS score of 8.6, this vulnerability is rated as High. The risk is significant as it allows unauthenticated remote attackers to exploit the vulnerability without needing any credentials. The potential for service disruption is critical, especially for internet-facing devices. Immediate action is recommended to patch affected systems.

Fast facts ⚡

  • Vulnerability Type: Denial of Service (DoS)
  • CVSS Score: 8.6 (High)
  • Exploitation: Requires IPv6 over IPsec VPN
  • Workarounds: None available
  • Fixed Software: Updates released, specific versions not listed

For leadership 🧭

Executive summary. Firepower 2100 Series firewalls running Cisco Secure Firewall ASA or FTD software can be forced to reload by an unauthenticated attacker sending crafted IPv6 traffic over an IPsec VPN, cutting the firewall’s protection and connectivity until it recovers. As there is no workaround, patching is the only mitigation and should be scheduled as soon as a maintenance window allows.

Why it matters:

  • Any Firepower 2100 Series device with IKEv1 or IKEv2 IPsec VPN enabled, IPv6 active on the RADIUS-facing interface, and an ACL permitting IP traffic is exposed to this reload trigger.
  • No authentication or user interaction is needed, so the attack surface is anyone who can reach the IPsec VPN endpoint over IPv6.
  • A successful reload takes down the firewall’s inspection and VPN termination functions, disrupting all traffic and remote-access sessions passing through it.
  • With no workaround published, sites cannot mitigate through configuration changes alone and must rely on the vendor’s fixed software.

Now / Next / Later:

  • Now: Identify every Firepower 2100 Series device running ASA or FTD software with IPsec VPN and IPv6 enabled on RADIUS-facing interfaces, and confirm which ones are reachable from untrusted networks.
  • Next: Schedule an upgrade to the first fixed release of Cisco Secure Firewall ASA or FTD Software for each identified device during the next change window, prioritising internet-facing units.
  • Later: Add IPv6-over-IPsec exposure and RADIUS proxy configuration to routine firewall hardening reviews so similar reload-triggering paths are caught before future advisories are needed.