ZeroHour
The Hacker Newspublished ()ingested @TheHackersNews

Cisco Issues Urgent Fix for ASA and FTD Software Vulnerability Under Active Attack

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2024-20329
A vulnerability in the SSH subsystem of Cisco Adaptive Security Appliance (ASA) Software could allow an authenticated, remote attacker to execute operating syst

A vulnerability in the SSH subsystem of Cisco Adaptive Security Appliance (ASA) Software could allow an authenticated, remote attacker to execute operating system commands as root. This vulnerability is due to insufficient validation of user input. An attacker could exploit this vulnerability by submitting crafted input when executing remote CLI commands over SSH. A successful exploit could allow the attacker to execute commands on the underlying operating system with root-level privileges. An attacker with limited user privileges could use this vulnerability to gain complete control over the system.

NVD description · AI analysis pending
9.91%
  • cisco adaptive security appliance software
CVE-2024-20412
A vulnerability in Cisco Firepower Threat Defense (FTD) Software for Cisco Firepower 1000, 2100, 3100, and 4200 Series could allow an unauthenticated, local att

A vulnerability in Cisco Firepower Threat Defense (FTD) Software for Cisco Firepower 1000, 2100, 3100, and 4200 Series could allow an unauthenticated, local attacker to access an affected system using static credentials. This vulnerability is due to the presence of static accounts with hard-coded passwords on an affected system. An attacker could exploit this vulnerability by logging in to the CLI of an affected device with these credentials. A successful exploit could allow the attacker to access the affected system and retrieve sensitive information, perform limited troubleshooting actions, modify some configuration options, or render the device unable to boot to the operating system, requiring a reimage of the device.

NVD description · AI analysis pending
8.4<1%
  • cisco secure firewall threat defense
CVE-2024-20424
A vulnerability in the web-based management interface of Cisco Secure Firewall Management Center (FMC) Software, formerly Firepower Management Center Software,

A vulnerability in the web-based management interface of Cisco Secure Firewall Management Center (FMC) Software, formerly Firepower Management Center Software, could allow an authenticated, remote attacker to execute arbitrary commands on the underlying operating system as root. This vulnerability is due to insufficient input validation of certain HTTP requests. An attacker could exploit this vulnerability by authenticating to the web-based management interface of an affected device and then sending a crafted HTTP request to the device. A successful exploit could allow the attacker to execute arbitrary commands with root permissions on the underlying operating system of the Cisco FMC device or to execute commands on managed Cisco Firepower Threat Defense (FTD) devices. To exploit this vulnerability, the attacker would need valid credentials for a user account with at least the role of Security Analyst (Read Only).

NVD description · AI analysis pending
9.9<1%
  • cisco secure firewall management center
CVE-2024-20481
Unauthenticated Remote Access VPN DoS in Cisco ASA and FTD Software

CVE-2024-20481 is a denial-of-service vulnerability in the Remote Access VPN (RAVPN) service of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software, caused by resource exhaustion (CWE-772). An unauthenticated, remote attacker can trigger it by sending a large number of VPN authentication requests to an affected device, consistent with the large-scale VPN brute-force activity Cisco Talos has documented. A successful attack exhausts device resources and causes a denial of service of the RAVPN service, potentially requiring a device reload to restore VPN service, though non-VPN functionality is unaffected. Only ASA and FTD devices with the RAVPN service enabled are affected. The flaw is under active exploitation: CISA added it to the Known Exploited Vulnerabilities catalog on 2024-10-24, and trade press reports Cisco issued urgent fixes for this actively exploited bug.

Do: Apply the fixed ASA/FTD Software releases specified in Cisco's advisory for CVE-2024-20481, or apply Cisco's documented mitigations (such as rate-limiting/throttling VPN authentication attempts) if patching is not immediately possible. Check RAVPN devices for bursts of failed or unusual VPN authentication requests consistent with brute-forcing, and restrict or disable internet-exposed RAVPN where it is not needed. Per CISA KEV guidance, apply vendor mitigations or discontinue use of the product if mitigations are unavailable.

5.816% KEV
  • Cisco Adaptive Security Appliance (ASA) Software
  • Cisco Firepower Threat Defense (FTD) Software
masshundreds of thousands of internet-exposed Cisco ASA/FTD appliances, of which the RAVPN-enabled subset is directly vulnerable
Full article505 words · extracted from thehackernews.com · click to collapse

Ravie LakshmananOct 24, 2024Vulnerability / Network Security

Cisco on Wednesday said it has released updates to address an actively exploited security flaw in its Adaptive Security Appliance (ASA) that could lead to a denial-of-service (DoS) condition.

The vulnerability, tracked as CVE-2024-20481 (CVSS score: 5.8), affects the Remote Access VPN (RAVPN) service of Cisco ASA and Cisco Firepower Threat Defense (FTD) Software.

Arising due to resource exhaustion, the security flaw could be exploited by unauthenticated, remote attackers to cause a DoS of the RAVPN service.

"An attacker could exploit this vulnerability by sending a large number of VPN authentication requests to an affected device," Cisco said in an advisory. "A successful exploit could allow the attacker to exhaust resources, resulting in a DoS of the RAVPN service on the affected device."

Restoration of the RAVPN service may require a reload of the device depending on the impact of the attack, the networking equipment company added.

While there are no direct workarounds to address CVE-2024-20481, Cisco said customers can follow recommendations to counter password spraying attacks -

  • Enable logging
  • Configure threat detection for remote access VPN services
  • Apply hardening measures such as disabling AAA authentication, and
  • Manually block connection attempts from unauthorized sources

It's worth noting that the flaw has put to use in a malicious context by threat actors as part of a large-scale brute-force campaign targeting VPNs, and SSH services.

Earlier this April, Cisco Talos flagged a spike in brute-force attacks against Virtual Private Network (VPN) services, web application authentication interfaces, and SSH services since March 18, 2024.

These attacks singled out a wide range of equipment from different companies, including Cisco, Check Point, Fortinet, SonicWall, MikroTik, Draytek, and Ubiquiti.

"The brute-forcing attempts use generic usernames and valid usernames for specific organizations," Talos noted at the time. "These attacks all appear to be originating from TOR exit nodes and a range of other anonymizing tunnels and proxies."

Cisco has also released patches to remediate three other critical flaws in FTD Software, Secure Firewall Management Center (FMC) Software, and Adaptive Security Appliance (ASA), respectively -

  • CVE-2024-20412 (CVSS score: 9.3) - A presence of static accounts with hard-coded passwords vulnerability in FTD Software for Cisco Firepower 1000, 2100, 3100, and 4200 Series that could allow an unauthenticated, local attacker to access an affected system using static credentials
  • CVE-2024-20424 (CVSS score: 9.9) - An insufficient input validation of HTTP requests vulnerability in the web-based management interface of FMC Software that could allow an authenticated, remote attacker to execute arbitrary commands on the underlying operating system as root
  • CVE-2024-20329 (CVSS score: 9.9) - An insufficient validation of user input vulnerability in the SSH subsystem of ASA that could allow an authenticated, remote attacker to execute operating system commands as root

With security vulnerabilities in networking devices emerging as a center point of nation-state exploitations, it's essential that users move quickly to apply the latest fixes.

Found this article interesting? Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post.

Text extracted automatically; images, tables and formatting may be missing. Original: https://thehackernews.com/2024/10/cisco-issues-urgent-fix-for-asa-and-ftd.html