Six advisories are included in the semi-annual Cisco Adaptive Security Appliance Software (ASA), Firepower Management Center (FMC) Software, and Firepower Threat Defense (FTD) Software Securi
Summary
Six advisories are included in the semi-annual Cisco Adaptive Security Appliance Software (ASA), Firepower Management Center (FMC) Software, and Firepower Threat Defense (FTD) Software Security Advisory bundled publication
Affected platforms
The following platforms are known to be affected:
Threat details
Introduction
Cisco has released six security advisories that cover six vulnerabilities in its semi-annual bundle of Cisco Adaptive Security Appliance Software (ASA), Firepower Management Center (FMC) Software, and Firepower Threat Defense (FTD) Software Advisories.
The one high impact advisory concerns a SQL injection vulnerability, which when exploited, could allow an authenticated, remote attacker to obtain any data from the database, execute arbitrary commands on the underlying operating system, and elevate privileges to root. To exploit this vulnerability, an attacker would need at least 'Read Only' user credentials.
The five medium impact advisories included in the bundle address five bypass vulnerabilities. A remote, unauthenticated attacker could exploit some of these vulnerabilities to access otherwise controlled areas of an affected system.
Remediation advice
Affected organisations are encouraged to review May 2024 Cisco ASA, FMC, and FTD Software Security Advisory Bundled Publication and the following Cisco Security Advisories and apply the necessary updates or workarounds.
Remediation steps
Definitive source of threat updates
CVE Vulnerabilities
Last edited: 28 May 2024 3:16 pm