An authenticated VPN user can send crafted HTTP requests to the SSL VPN web server on Cisco ASA and FTD, creating or deleting operating system files and potentially forcing a reboot to restore VPN service.
Every CISA KEV addition, plus critical-severity flaws in the kit that sits at the edge of a network: firewalls, VPN gateways, load balancers, routers, switches and management consoles.
Colour on the left of each entry is the CVSS severity. A pink CISA KEV badge means the flaw is being exploited right now — treat those first, whatever the score says. How each post is sourced and checked is set out in the methodology.
Cisco Secure Firewall Adaptive Security Appliance and Secure Firewall Threat Defense Software Network Address Translation DNS Inspection Denial of Service Vulnerability
A DNS inspection bug in Cisco ASA and FTD firewalls lets an unauthenticated attacker crash the device with crafted DNS packets whenever NAT and DNS inspection are both enabled.
Cisco Secure Firewall Adaptive Security Appliance and Secure Firewall Threat Defense Software SSL/TLS Certificate Denial of Service Vulnerability
Crafted DNS packets that hit a static NAT rule with DNS inspection enabled can trigger a certificate-parsing bug in ASA and FTD software, forcing an unauthenticated reload of the firewall.
Cisco Secure Firewall Adaptive Security Appliance and Secure Firewall Threat Defense Software Remote Access SSL VPN Denial of Service Vulnerabilities
Two unauthenticated denial-of-service flaws in the VPN and management web servers of Cisco ASA and FTD firewalls let a crafted request or HTTP packet freeze VPN authentication or reload the device outright.
Cisco Secure Firewall Adaptive Security Appliance and Secure Firewall Threat Defense Software Remote Access VPN Web Server Denial of Service Vulnerability
An authenticated VPN user can crash an ASA or FTD firewall’s remote access SSL VPN web server with a malformed HTTP header, forcing an unplanned reload with no workaround available.
Cisco Secure Firewall Management Center Software Authorization Bypass Vulnerabilities
Low-privileged users on a multi-domain Cisco FMC deployment can pull troubleshoot files and generated reports belonging to other domains, breaking the confidentiality boundary between tenants.
Cisco Secure Firewall Management Center Software Command Injection Vulnerability
An admin-authenticated command injection in Cisco FMC’s web interface lets a logged-in administrator break out of lockdown mode restrictions to run root commands on the underlying OS.
Cisco Secure Firewall Management Center and Secure Firewall Threat Defense Software Command Injection Vulnerability
A CLI input-validation flaw lets an already-authenticated FMC or FTD Administrator break out of a locked-down command prompt into full root access on the underlying OS.
Cisco Secure Firewall Management Center Software HTML Injection Vulnerability
A low-privilege, read-only FMC analyst account can inject HTML into device-generated documents, enabling arbitrary file reads from the underlying OS and SSRF against other reachable systems.
Cisco Secure Firewall Management Center Software RADIUS Remote Code Execution Vulnerability
An unauthenticated attacker can smuggle shell commands through the login fields on Cisco Secure Firewall Management Center whenever RADIUS authentication is switched on, gaining high-privilege code execution.