Cisco warns of ASA and FTD VPN flaw exploited to crash devices

Summary

Cisco has issued a warning about a critical denial-of-service vulnerability affecting their Secure Firewall ASA and Threat Defense (FTD) software. The flaw is actively being exploited in the wild, allowing remote attackers to crash affected devices.

IFF Assessment

FOE

This vulnerability allows attackers to crash critical network devices, directly impacting the availability and security of network infrastructure, which is detrimental to defenders.

Severity

8.2 High (AI Estimated)

The vulnerability allows for remote code execution and denial-of-service, with a high impact on confidentiality, integrity, and availability, and is exploitable without authentication over the network.

Defender Context

This vulnerability highlights the importance of keeping network security devices patched and updated promptly. Defenders should prioritize patching Cisco ASA and FTD devices to mitigate the risk of exploitation. Monitoring network traffic for signs of exploitation attempts related to this flaw is also crucial.

Read Full Story →