By Interestana AI Editorial — AI-drafted, human-overseen. How we report
Cisco Warns of Exploited VPN Flaw Crashing Firewalls
Cisco issued a warning on March 18, 2024, detailing a high-severity denial-of-service (DoS) vulnerability in its Secure Firewall ASA and Secure Firewall Threat Defense (FTD) software. This flaw, identified as CVE-2024-20933, is actively being exploited in the wild, with attackers leveraging it to remotely crash affected devices. The vulnerability specifically impacts the VPN functionality of these security appliances. Cisco's advisory states that successful exploitation could lead to a device reload, causing a denial of service for legitimate users attempting to establish VPN connections. The company has confirmed that the vulnerability is being exploited in attacks, although it has not provided specific details on the nature or scale of these attacks. The affected products include Cisco Secure Firewall ASA versions 9.16, 9.17, 9.18, and 9.19, as well as Cisco Secure Firewall FTD versions 7.0, 7.1, 7.2, and 7.3. Cisco has released software updates to address this vulnerability. Customers are strongly advised to apply these updates as soon as possible to mitigate the risk of exploitation. The company has also provided workarounds for customers who cannot immediately apply the patches, though these workarounds may not fully eliminate the risk. The Secure Firewall ASA (Adaptive Security Appliance) is a widely deployed network security device that provides firewall, VPN, and intrusion prevention capabilities for enterprise networks. The Secure Firewall FTD (Firewall Threat Defense) is a more integrated platform that combines firewall, intrusion prevention, and advanced threat defense features. The exploitation of this vulnerability highlights the ongoing threat posed by sophisticated attackers targeting critical network infrastructure. Organizations relying on these Cisco products for their network security are urged to prioritize the application of the provided security patches to prevent potential service disruptions and unauthorized access. The advisory did not specify the exact method of exploitation but indicated that it could be achieved remotely, meaning attackers do not need direct access to the network to trigger the vulnerability. This situation underscores the importance of maintaining up-to-date security software and diligently applying vendor-provided patches to protect against emerging threats. Cisco is committed to providing timely security advisories and solutions to its customers, and this incident serves as a reminder of the dynamic nature of cybersecurity threats.
Original source — read the full reporting at the publisher:
Read on BleepingComputerGet the weekly AI digest
AI news + new model releases, weekly. Drafted by our agents, reviewed by humans.