Cisco Secure Firewall Adaptive Security Appliance and Secure Firewall Threat Defense Software SSL/TLS Certificate Denial of Service Vulnerability

🚨 SEVERITY: HIGH — CVSS 8.6 Security Advisory

TL;DR 📌

A high-severity vulnerability in Cisco Secure Firewall ASA and FTD Software could allow unauthenticated remote attackers to trigger a denial of service (DoS) by sending a crafted SSL/TLS certificate. Immediate action is required to patch affected systems.

What happened 🕵️‍♂️

Cisco has identified a vulnerability in the certificate processing of its Secure Firewall Adaptive Security Appliance (ASA) Software and Secure Firewall Threat Defense (FTD) Software. This flaw allows an unauthenticated remote attacker to send a specially crafted SSL/TLS certificate to an affected device, potentially causing it to reload unexpectedly and resulting in a denial of service (DoS) condition.

Affected products 🖥️

The vulnerability affects:

  • Cisco Secure Firewall ASA Software Release 9.15 and earlier
  • Cisco Secure Firewall FTD Software Release 6.7 and earlier

Devices with an SSL/TLS listening socket running these software versions are at risk.

Fixed software 🔧

Upgrade to the first fixed release in your train (or later):

Release / Product First Fixed Release Notes
9.15 and earlier Migrate to a fixed release.
6.7 and earlier Migrate to a fixed release.
1.0 Initial public release.

Workarounds 🧯

There are no workarounds available for this vulnerability.

Risk in context 🎯

With a CVSS score of 8.6, this vulnerability is rated as High severity. The risk is significant due to the potential for unauthenticated remote exploitation, which could lead to service outages. Organizations using affected products should prioritize patching to mitigate the risk of a DoS attack.

Fast facts ⚡

  • Vulnerability: SSL/TLS Certificate Denial of Service
  • CVSS Score: 8.6 (High)
  • Attack Vector: Remote, unauthenticated
  • Impact: Device reload leading to DoS
  • Workarounds: None available

For leadership 🧭

Executive summary. Any Cisco ASA or FTD firewall with an SSL/TLS listening socket can be rebooted at will by a remote attacker who need not authenticate, taking down the firewall and everything behind it. There is no workaround, so this needs to move onto the patching schedule as a priority rather than waiting for a routine maintenance cycle.

Why it matters:

  • The flaw sits in certificate processing on Secure Firewall ASA (9.15 and earlier) and FTD (6.7 and earlier) — any device presenting an SSL/TLS listening socket is a reachable target.
  • No authentication is required: a single crafted certificate sent to the listener is enough to force a reload, meaning exposure is tied purely to network reachability of the SSL/TLS service.
  • A firewall reload is not a minor blip — it drops the inspection and access-control point for everything behind it, so a single crafted packet can disrupt an entire protected network segment.
  • There is no workaround, so mitigation depends entirely on getting to a fixed software release.

Now / Next / Later:

  • Now: Identify every ASA and FTD device running 9.15/6.7 or earlier with an SSL/TLS listening socket exposed to any untrusted network, and treat them as immediately at risk pending patching.
  • Next: Schedule an upgrade of affected ASA and FTD devices to the first fixed release for their train during the next available change window, since no interim workaround exists.
  • Later: Build SSL/TLS-facing firewall software versions into routine patch tracking so future certificate-processing advisories are picked up and scheduled before they become urgent.