Cisco Secure Firewall Adaptive Security Appliance Software, Secure Firewall Threat Defense Software, IOS Software, IOS XE Software, and IOS XR Software Web Services Remote Code Execution Vulnerability
TL;DR 📌
A critical vulnerability has been identified in the web services of Cisco Secure Firewall ASA, Secure Firewall FTD, IOS, IOS XE, and IOS XR Software. This flaw could allow unauthenticated or authenticated remote attackers to execute arbitrary code on affected devices. Cisco has released fixed software to address this issue, and there are no workarounds available.
What happened 🕵️♂️
A vulnerability in the web services of Cisco Secure Firewall ASA and FTD Software allows unauthenticated remote attackers to execute arbitrary code on affected devices. For IOS, IOS XE, and IOS XR Software, the vulnerability can be exploited by authenticated remote attackers with low user privileges. This vulnerability arises from improper validation of user-supplied input in HTTP requests, potentially leading to complete device compromise.
Affected products 🖥️
The following Cisco products are affected by this vulnerability:
- Cisco Secure Firewall ASA Software
- Cisco Secure Firewall FTD Software
- Cisco IOS Software (with Remote Access SSL VPN feature enabled)
- Cisco IOS XE Software (with Remote Access SSL VPN feature enabled)
- Cisco IOS XR Software (32-bit on ASR 9001 Routers with HTTP server enabled)
Fixed software 🔧
Upgrade to the first fixed release in your train (or later):
| Release / Product | First Fixed Release | Notes |
|---|---|---|
| 6.8 | ASR 9001 | |
| 6.9 | ASR 9001 | |
| 1.0 | Initial public release. | |
| Cisco Secure Firewall ASA | Not specified | |
| Cisco Secure FMC | Not specified | |
| Cisco Secure FTD | Not specified | |
| Cisco IOS | Not specified | |
| Cisco IOS XE | Not specified | |
| Cisco IOS XR | 6.8 | Earlier than 6.8 |
| Cisco IOS XR | 6.9 | Earlier than 6.9 |
Workarounds 🧯
There are no workarounds available to mitigate this vulnerability.
Risk in context 🎯
This vulnerability has a CVSS score of 9.0, categorizing it as Critical. The exposure risk is significant, as unauthenticated attackers can exploit the vulnerability remotely. The lack of workarounds increases the urgency for organizations to apply the necessary updates promptly.
Fast facts ⚡
- Vulnerability Type: Remote Code Execution
- CVSS Score: 9.0 (Critical)
- Attack Vector: Remote, unauthenticated for ASA/FTD; authenticated for IOS/IOS XE/IOS XR
- Impact: Complete device compromise possible
- Workarounds: None available
For leadership 🧭
Executive summary. Cisco ASA and FTD firewalls can be remotely compromised by unauthenticated attackers through a web services flaw, with no workaround available. This should be treated as an emergency patching item given the perimeter role these devices play.
Why it matters:
- ASA and Firewall Threat Defense boxes typically sit at the network edge, so a flaw exploitable without authentication turns any reachable management or web interface into a route to full device compromise.
- IOS, IOS XE and IOS XR are also affected where Remote Access SSL VPN or the HTTP server is enabled, meaning routers and switches used for remote access are in scope, not just dedicated firewalls.
- There are no workarounds, so the only mitigation until patched is upgrading, restricting access to the web services interface, or removing the affected feature (SSL VPN or HTTP server) where feasible.
- A CVSS score of 9.0 combined with unauthenticated remote code execution on perimeter firewall software means a single exposed device could give an attacker a foothold inside the network.
Now / Next / Later:
- Now: Identify every ASA, FTD, IOS, IOS XE and IOS XR device with web services, HTTP server, or Remote Access SSL VPN enabled and check exposure to untrusted networks.
- Next: Schedule an emergency change window to upgrade affected ASA, FTD, IOS, IOS XE and IOS XR devices to the first fixed release for their train, prioritising internet-facing units.
- Later: Build a standing inventory of which devices run web services, HTTP servers, or SSL VPN features so future advisories affecting these components can be triaged and patched faster.