Skip to main content

35 advisories are included in the semi-annual Cisco Adaptive Security Appliance Software (ASA), Firepower Management Center (FMC) Software, and Firepower Threat Defense (FTD) Software Securit

Summary

35 advisories are included in the semi-annual Cisco Adaptive Security Appliance Software (ASA), Firepower Management Center (FMC) Software, and Firepower Threat Defense (FTD) Software Security Advisory bundled publication

Affected platforms

The following platforms are known to be affected:

Threat details

Introduction

Cisco has released 35 security advisories that cover 51 vulnerabilities in its semi-annual bundle of Cisco Adaptive Security Appliance Software (ASA), Firepower Management Center (FMC) Software, and Firepower Threat Defense (FTD) Software Advisories.

The bundled publication includes 3 advisories with a critical security impact rating, 11 with high security impact, 20 advisories with medium impact, and 1 advisory rated as informational. Of these advisories, special attention should be given to the following two medium impact advisories, listed in the following section due to exploitation or availability of exploit code.

In addition, three critical security impact advisories also warrant close inspection. Two vulnerabilities address command injection vulnerabilities, which if exploited, could allow an authenticated, remote attacker to execute commands as root. The third critical advisory concerns a static credential vulnerability that could allow an attacker to access the affected system and retrieve sensitive information, perform limited troubleshooting actions, modify some configuration options, or render the device unable to boot to the operating system, requiring a re-image of the device.

Much more information about the other advisories not described in this cyber alert can be found in the October 2024 Cisco ASA, FMC, and FTD Software Security Advisory Bundled Publication.

Exploitation in the wild and PoC exploit code available

Remediation advice

Affected organisations are encouraged to review October 2024 Cisco ASA, FMC, and FTD Software Security Advisory Bundled Publication and its linked advisories and apply any relevant security updates.

Additional mitigation guidance is available in Recommendations Against Password Spray Attacks Aimed at Remote Access VPN Services in Secure Firewall TechNote.

Definitive source of threat updates

CVE Vulnerabilities

Last edited: 24 October 2024 4:00 pm