ZeroHour
Cisco Security Advisoriespublished ()ingested
Part of a story covered by 9 sources: “Cisco Patches Nine Secure Firewall ASA/FTD Vulnerabilities, Including ACL Bypass and Eight Denial-of-Service Flaws” — merged summary and timeline →

Cisco Secure Firewall Adaptive Security Appliance and Secure Firewall Threat Defense Software Object Group Access Control List Bypass Vulnerabilities

mediumAdvisoryimportance 48
AI summary · glm-5.3-flash

Cisco patched ACL Object Group Search bypass flaws in ASA and FTD firewall software that let unauthenticated attackers reach protected networks.

Cisco disclosed multiple vulnerabilities in the ACL Object Group Search implementation of Secure Firewall ASA and FTD Software, caused by a logic error in populating group access control policies. An unauthenticated remote attacker could send traffic that should be blocked through the device, bypassing configured access controls. Cisco has released software updates; no exploitation is mentioned.

  • Logic error in OGS group ACP population causes the ACL bypass
  • Unauthenticated remote attacker can pass traffic that should be blocked
  • Affects both Cisco ASA and FTD firewall software
  • Software updates released by Cisco
Full article

Multiple vulnerabilities in the access control list (ACL) Object Group Search (OGS) implementation of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to bypass configured access controls. These vulnerabilities are due to a logic error in populating group access control policies (ACPs) with OGS configured. An attacker could exploit these vulnerabilities by sending traffic that should be blocked through the device. A successful exploit could allow the attacker to bypass access controls and reach devices in protected networks. Cisco has released software updates that address…

This source does not provide full text. Read it at sec.cloudapps.cisco.com.