PSA: Vulnerabilities in Cisco products – updates required

[German]Some Cisco products contains contains critical vulnerabilities. These vulnerabilities are quoted with warning level 10 of 10. Cisco Firewalls and Applicance should be updated as as soon as possible.


Cisco has published an advisory Cisco Adaptive Security Appliance Remote Code Execution and Denial of Service Vulnerability, dated January 29, 2018.

A vulnerability in the Secure Sockets Layer (SSL) VPN functionality of the Cisco Adaptive Security Appliance (ASA) Software could allow an unauthenticated, remote attacker to cause a reload of the affected system or to remotely execute code.

This vulnerability affects Cisco ASA Software that is running on the following Cisco products, if the webvpn feature is enabled:

  • 3000 Series Industrial Security Appliance (ISA)
  • ASA 5500 Series Adaptive Security Appliances
  • ASA 5500-X Series Next-Generation Firewalls
  • ASA Services Module for Cisco Catalyst 6500 Series Switches and Cisco 7600 Series Routers
  • ASA 1000V Cloud Firewall
  • Adaptive Security Virtual Appliance (ASAv)
  • Firepower 2100 Series Security Appliance
  • Firepower 4110 Security Appliance
  • Firepower 9300 ASA Security Module
  • Firepower Threat Defense Software (FTD)

To determine whether a vulnerable version of Cisco ASA Software is running on a device, administrators can use the show version command in the CLI (as detailed here). There are no workarounds that address this vulnerability. But Cisco has released software updates that address this vulnerability. Further details may be obtained from the security advisory.


This entry was posted in devices, Security and tagged , . Bookmark the permalink.

Leave a Reply

Your email address will not be published. Required fields are marked *