Cisco Secure Firewall Adaptive Security Appliance and Secure Firewall Threat Defense Software Remote Access VPN Web Server Denial of Service Vulnerability
TL;DR 📌
A denial of service (DoS) vulnerability has been identified in the Remote Access SSL VPN service for Cisco Secure Firewall ASA and FTD Software. This flaw could allow an authenticated attacker to cause the device to reload unexpectedly. Cisco has released updates to address this issue, but no workarounds are available.
What happened 🕵️♂️
A vulnerability in the Remote Access SSL VPN service for Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software has been discovered. This vulnerability arises from incomplete error checking when parsing an HTTP header field value. An authenticated attacker could exploit this by sending a crafted HTTP request, leading to an unexpected device reload and resulting in a denial of service (DoS) condition.
Affected products 🖥️
- Cisco Secure Firewall Adaptive Security Appliance (ASA) Software
- Cisco Secure Firewall Threat Defense (FTD) Software
Fixed software 🔧
Upgrade to the first fixed release in your train (or later):
| Release / Product | First Fixed Release | Notes |
|---|---|---|
| 7.4 | Cisco_FTD_Hotfix_EI-7.4.2.4-2.sh.REL.tar Cisco_FTD_SSP_FP1K_Hotfix_EI-7.4.2.4-2.sh.REL.tar Cisco_FTD_SSP_FP2K_Hotfix_EI-7.4.2.4-2.sh.REL.tar Cisco_FTD_SSP_FP3K_Hotfix_EI-7.4.2.4-2.sh.REL.tar Cisco_FTD_SSP_Hotfix_EI-7.4.2.4-2.sh.REL.tar Cisco_Secure_FW_TD_4200_Hotfix_EI-7.4.2.4-2.sh.REL.tar | |
| 1.0 | Initial public release. |
Workarounds 🧯
There are no workarounds available for this vulnerability.
Risk in context 🎯
The vulnerability has a CVSS score of 7.7, categorizing it as High severity. It requires authentication to exploit, but if successfully executed, it could lead to a denial of service, impacting device availability. Organizations should prioritize applying the available fixes to mitigate this risk.
Fast facts ⚡
- Vulnerability: Remote Access VPN Web Server DoS
- CVSS Score: 7.7 (High)
- Impact: Device reload leading to DoS
- Authentication Required: Yes
- Workarounds: None available
For leadership 🧭
Executive summary. A high-severity flaw in the Remote Access SSL VPN service on Cisco ASA and FTD firewalls lets an already-authenticated user crash the device with a crafted HTTP request, causing an unplanned reload and loss of firewall availability. There is no workaround, so patching on the applicable train is the only fix and should be scheduled promptly.
Why it matters:
- The flaw sits in the Remote Access SSL VPN web server itself, so any ASA or FTD device terminating clientless or AnyConnect-style VPN sessions is exposed to this request path.
- Exploitation causes an unexpected device reload, meaning a full firewall outage rather than a partial service degradation, affecting all traffic the device handles, not just VPN sessions.
- No workaround exists, so mitigation depends entirely on deploying the fixed hotfix builds listed for the 7.4 train and equivalent Firepower appliance images.
- The bug requires authentication, so exposure is limited to users who already hold valid VPN credentials rather than anonymous internet traffic.
Now / Next / Later:
- Now: Identify every ASA and FTD device offering Remote Access SSL VPN and confirm which software train and hotfix level each is running.
- Next: Apply the appropriate fixed hotfix (Cisco_FTD_Hotfix_EI-7.4.2.4-2.sh.REL.tar or the matching FP1K/FP2K/FP3K/SSP/4200 variant) during the next maintenance window, since no workaround is available to bridge the gap.
- Later: Bring VPN-terminating firewalls into a regular patch cadence tied to Cisco security advisories, given that this service has no interim mitigation options when flaws are found.