Cisco Secure Firewall Adaptive Security Appliance and Secure Firewall Threat Defense Software Remote Access SSL VPN Denial of Service Vulnerabilities
TL;DR 📌
Multiple vulnerabilities have been identified in Cisco Secure Firewall Adaptive Security Appliance (ASA) and Secure Firewall Threat Defense (FTD) Software, allowing unauthenticated remote attackers to cause denial of service (DoS) conditions. Cisco has released software updates to address these vulnerabilities, but there are no workarounds available.
What happened 🕵️♂️
Cisco has disclosed vulnerabilities in the management and VPN web servers of its Secure Firewall ASA and FTD Software. These vulnerabilities stem from improper validation of user-supplied input, enabling attackers to send crafted HTTP requests that could lead to the device becoming unresponsive or unexpectedly reloading, resulting in a denial of service (DoS) condition.
Affected products 🖥️
The vulnerabilities affect:
- Cisco Secure Firewall Adaptive Security Appliance (ASA) Software
- Cisco Secure Firewall Threat Defense (FTD) Software
Fixed software 🔧
Upgrade to the first fixed release in your train (or later):
| Release / Product | First Fixed Release | Notes |
|---|---|---|
| 1.0 | Initial public release. |
Workarounds 🧯
There are no workarounds available to mitigate these vulnerabilities.
Risk in context 🎯
The vulnerabilities have a CVSS score of 8.6, categorizing them as High severity. They are exploitable remotely without authentication, which increases the risk significantly. Successful exploitation could lead to service disruptions, impacting availability.
Fast facts ⚡
- CVSS Score: 8.6 (High)
- Vulnerabilities: Denial of Service (DoS)
- Exploitation: Requires crafted HTTP requests
- Workarounds: None available
- Fixed Software: Updates released; specific versions not listed
For leadership 🧭
Executive summary. Firewalls running Cisco ASA or FTD software can be knocked offline remotely by anyone able to reach the management or SSL VPN web interface, with no login required and no workaround to fall back on. Given these appliances typically sit at the network edge and often terminate remote access VPN, this needs scheduling into the next available patch window rather than left for routine maintenance.
Why it matters:
- The flaw sits in the management and VPN web servers of ASA and FTD, the same interfaces used for device administration and remote access SSL VPN termination, so it’s exposed wherever those services are reachable.
- No authentication is required to trigger the crash or reload, meaning anyone who can send a crafted HTTP request to the exposed interface can attempt it.
- There are no workarounds, so mitigation depends entirely on upgrading, leaving affected devices exposed until patched.
- A successful DoS reload of an ASA or FTD appliance can interrupt firewall and VPN service for everyone relying on that device, not just a single session.
Now / Next / Later:
- Now: Identify every ASA and FTD device with its management interface or SSL VPN web service reachable from outside your trusted networks, and restrict access to those interfaces to known management sources immediately.
- Next: Upgrade all affected ASA and FTD devices to the first fixed release for their software train during the next available change window, since no workaround exists to buy time.
- Later: Review firewall and edge device management access policies so that administrative and VPN web interfaces are never exposed to untrusted networks by default, reducing exposure to future advisories of this kind.