Cisco Secure Firewall Threat Defense Software Geolocation Remote Access VPN Bypass Vulnerability

🚨 SEVERITY: MEDIUM — CVSS 5.8 Security Advisory

TL;DR 📌

A medium-severity vulnerability has been identified in the Geolocation-Based Remote Access VPN feature of Cisco Secure Firewall Threat Defense Software. This flaw allows unauthenticated attackers to bypass security policies, potentially granting unauthorized access to restricted networks. No workarounds are available, and software updates are necessary to mitigate the risk.

What happened 🕵️‍♂️

A vulnerability in Cisco Secure Firewall Threat Defense (FTD) Software’s Geolocation-Based Remote Access (RA) VPN feature could enable an unauthenticated, remote attacker to bypass configured policies that control HTTP connections based on geographical location. This issue arises from incomplete URL parsing, allowing attackers to exploit it by sending crafted HTTP connections. Successful exploitation could lead to unauthorized access to networks that should otherwise be protected.

Affected products 🖥️

The vulnerability affects Cisco devices running Cisco Secure FTD Software Release 7.7.0 with Geolocation-Based RA VPN enabled. Other products, including Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Management Center (FMC) Software, are confirmed to be unaffected.

Fixed software 🔧

Upgrade to the first fixed release in your train (or later):

Release / Product First Fixed Release Notes
1.0 Initial public release.

Workarounds 🧯

There are no workarounds available to mitigate this vulnerability.

Risk in context 🎯

With a CVSS score of 5.8, this vulnerability is classified as medium severity. While it does not require authentication and poses a risk of unauthorized access, the lack of available workarounds necessitates prompt action to update affected systems. Organizations should prioritize patching to maintain their security posture.

Fast facts ⚡

  • Vulnerability: Geolocation Remote Access VPN Bypass
  • CVSS Score: 5.8 (Medium)
  • Exploitation: Unauthenticated access possible
  • Workarounds: None available
  • Fixed Software: Updates available; consult Cisco advisories

For leadership 🧭

Executive summary. Firewalls running Cisco Secure FTD 7.7.0 with Geolocation-Based Remote Access VPN enabled can be tricked into letting in connections that should have been blocked by location policy, without any credentials needed. There’s no workaround, so this needs a patch scheduled rather than left to sit.

Why it matters:

  • The bug sits in the Geolocation-Based RA VPN feature of Cisco Secure FTD 7.7.0, where incomplete URL parsing lets crafted HTTP connections slip past country-based access rules.
  • No authentication is required, so any remote party can attempt the bypass against a device relying on geolocation restrictions to keep certain regions out.
  • There are no workarounds, meaning firewalls in this configuration stay exposed to the bypass until the software is upgraded.
  • Cisco ASA and FMC software are confirmed unaffected, so exposure is limited to FTD deployments actively using this specific geolocation VPN feature.

Now / Next / Later:

  • Now: Check which of your Cisco Secure FTD devices are running Release 7.7.0 with Geolocation-Based RA VPN enabled, since these are the only configurations at risk.
  • Next: Schedule an upgrade to the first fixed FTD release for your train during your next change window, as no interim workaround exists to reduce exposure.
  • Later: Review reliance on geolocation-based access rules for VPN as a standalone control and pair it with additional authentication or network-layer restrictions so a single parsing flaw cannot fully bypass regional access policy.