35 advisories are included in the semi-annual Cisco Adaptive Security Appliance Software (ASA), Firepower Management Center (FMC) Software, and Firepower Threat Defense (FTD) Software Securit
Summary
35 advisories are included in the semi-annual Cisco Adaptive Security Appliance Software (ASA), Firepower Management Center (FMC) Software, and Firepower Threat Defense (FTD) Software Security Advisory bundled publication
Affected platforms
The following platforms are known to be affected:
Threat details
Introduction
Cisco has released 35 security advisories that cover 51 vulnerabilities in its semi-annual bundle of Cisco Adaptive Security Appliance Software (ASA), Firepower Management Center (FMC) Software, and Firepower Threat Defense (FTD) Software Advisories.
The bundled publication includes 3 advisories with a critical security impact rating, 11 with high security impact, 20 advisories with medium impact, and 1 advisory rated as informational. Of these advisories, special attention should be given to the following two medium impact advisories, listed in the following section due to exploitation or availability of exploit code.
In addition, three critical security impact advisories also warrant close inspection. Two vulnerabilities address command injection vulnerabilities, which if exploited, could allow an authenticated, remote attacker to execute commands as root. The third critical advisory concerns a static credential vulnerability that could allow an attacker to access the affected system and retrieve sensitive information, perform limited troubleshooting actions, modify some configuration options, or render the device unable to boot to the operating system, requiring a re-image of the device.
Much more information about the other advisories not described in this cyber alert can be found in the October 2024 Cisco ASA, FMC, and FTD Software Security Advisory Bundled Publication.
Exploitation in the wild and PoC exploit code available
Remediation advice
Affected organisations are encouraged to review October 2024 Cisco ASA, FMC, and FTD Software Security Advisory Bundled Publication and its linked advisories and apply any relevant security updates.
Additional mitigation guidance is available in Recommendations Against Password Spray Attacks Aimed at Remote Access VPN Services in Secure Firewall TechNote.
Definitive source of threat updates
CVE Vulnerabilities
Last edited: 24 October 2024 4:00 pm