ZeroHour
Infosecurity Magazinepublished ()ingested Sarah Coble

Cisco Flaw Affects Firewalls

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2020-3187
A vulnerability in the web services interface of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow

A vulnerability in the web services interface of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to conduct directory traversal attacks and obtain read and delete access to sensitive files on a targeted system. The vulnerability is due to a lack of proper input validation of the HTTP URL. An attacker could exploit this vulnerability by sending a crafted HTTP request containing directory traversal character sequences. An exploit could allow the attacker to view or delete arbitrary files on the targeted system. When the device is reloaded after exploitation of this vulnerability, any files that were deleted are restored. The attacker can only view and delete files within the web services file system. This file system is enabled when the affected device is configured with either WebVPN or AnyConnect features. This vulnerability can not be used to obtain access to ASA or FTD system files or underlying operating system (OS) files. Reloading the affected device will restore all files within the web services file system.

NVD description · AI analysis pending
9.197% PoC
  • cisco secure firewall threat defense
  • cisco asa 5505 firmware
  • cisco asa 5510 firmware
  • +1 more
CVE-2020-3259
Unauthenticated Memory-Disclosure Flaw in Cisco ASA and FTD Web Services

CVE-2020-3259 is an information-disclosure vulnerability in the web services interface of Cisco Adaptive Security Appliance (ASA) Software and Firepower Threat Defense (FTD) Software, caused by a buffer-tracking error when the device parses invalid URLs. An unauthenticated, remote attacker can trigger it by sending a crafted GET request to the web services interface, which allows retrieval of the device's memory contents and disclosure of confidential information. Only devices with specific AnyConnect and WebVPN configurations are affected, but those configurations are common on ASA/FTD firewalls deployed as enterprise edge and remote-access VPN gateways. Exploitation is confirmed in the wild: CISA added the bug to its Known Exploited Vulnerabilities catalog on 2024-02-15 with known ransomware use, and the Akira ransomware group (which the FBI says has extorted $42 million across roughly 250 attacks since March 2023) is actively exploiting it, with LockBit also scanning for vulnerable Cisco ASA devices. EPSS assigns a 71.8% probability of exploitation within 30 days, and no public proof-of-concept code is known.

Do: Upgrade affected ASA and FTD devices to the fixed releases listed in Cisco's security advisory for CVE-2020-3259; if patching is delayed, disable or restrict the web services interface (WebVPN/AnyConnect) to trusted source networks. Per the CISA KEV required action, apply vendor mitigations or discontinue use where mitigations are unavailable. Prioritize internet-facing VPN gateways and hunt for exploitation indicators (anomalous GET requests to the web services interface) given active Akira and LockBit targeting.

7.572% KEV ransomware
  • Cisco Adaptive Security Appliance (ASA) Software
  • Cisco Secure Firewall Threat Defense (FTD) Software
mass~100,000+ internet-exposed ASA/FTD devices with the web services (WebVPN/AnyConnect) interface enabled
CVE-2020-3452
Read-Only Path Traversal in Cisco ASA and Firepower Threat Defense (FTD)

Cisco Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD) contain an improper input validation flaw (CWE-20) in how HTTP requests process URLs. An attacker triggers it by sending a crafted HTTP request containing directory traversal character sequences to the web services interface of an affected device. A successful exploit is read-only: the attacker can view arbitrary files within the web services file system, potentially leaking sensitive device or configuration content, but cannot modify the device or take full control. Any organization running ASA or FTD software with the web services interface reachable — commonly an internet-facing VPN or web portal — is affected. The flaw is listed in CISA's Known Exploited Vulnerabilities catalog (added 2021-11-03) with a reported ~100% EPSS probability of exploitation, indicating it is being actively exploited in the wild; ransomware use is unknown.

Do: Apply Cisco's fixed software releases for ASA and FTD as directed in the vendor advisory. Until patched, restrict access to the device's web services/WebVPN interface to trusted source addresses or disable web services if not in use. Review device HTTP logs for crafted requests containing directory traversal sequences against the web portal, which would indicate exploitation attempts.

7.5100% KEV PoC ×3
  • Cisco Adaptive Security Appliance (ASA)
  • Cisco Firepower Threat Defense (FTD)
masson the order of hundreds of thousands of potentially affected deployments (internet-exposed ASA/FTD devices)
CVE-2021-34704
A vulnerability in the web services interface of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow

A vulnerability in the web services interface of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to trigger a denial of service (DoS) condition. This vulnerability is due to improper input validation when parsing HTTPS requests. An attacker could exploit this vulnerability by sending a malicious HTTPS request to an affected device. A successful exploit could allow the attacker to cause the device to reload, resulting in a DoS condition.

NVD description · AI analysis pending
7.51%
  • cisco secure firewall threat defense
  • cisco adaptive security appliance software
Full article351 words · extracted from infosecurity-magazine.com · click to collapse

A newly discovered vulnerability found in two devices made by Cisco could cause remote access to be disrupted.

The flaw – CVE-2021-34704 – was detected by Positive Technologies researcher Nikita Abramov in October in the firewalls of Cisco ASA (Adaptive Security Appliance) and Cisco FTD (Firepower Threat Defense).

If the vulnerability is exploited, the organization’s firewall will be weakened, leaving it more vulnerable to attack, and employees working remotely would be blocked from accessing their organization’s internal network. 

According to Abramov, an attacker does not require elevated privileges or special access to exploit the flaw. All it takes is the formation of a simple request, in which one of the parts is of a different size than that expected by the device. 

Further parsing of the request will trigger a buffer overflow/overrun as the amount of data in the buffer exceeds its storage capacity. The impacted system will then shut down abruptly and restart.

Abramov said: “If hackers disrupt the operation of Cisco ASA and Cisco FTD, a company will be left without a firewall and remote access (VPN). If the attack is successful, remote employees or partners will not be able to access the internal network of the organization, and access from the outside will be restricted. At the same time, firewall failure will reduce the protection of the company.”

Describing the impact such an outcome could have on an organization. Abramov said: “All this can negatively impact company processes, disrupt interactions between departments, and make the company vulnerable to targeted attacks.”

According to Forrester Research, Cisco is an enterprise firewall market leader that has deployed more than 1 million security appliances around the globe. 

An assessment of the flaw determined it to be of high severity with a CVSSv3.0 score of 8.6. A fix for the flaw has been created, and users are advised to follow the manufacturer’s recommendations outlined in its security advisory and install updates as soon as possible. 

Positive Technologies has previously discovered vulnerabilities in Cisco Firepower Device Manager (FDM) On-Box and critical flaws in Cisco ASA, such as CVE-2020-3187, CVE-2020-3259, and CVE-2020-3452.

Text extracted automatically; images, tables and formatting may be missing. Original: https://www.infosecurity-magazine.com/news/cisco-flaw-affects-firewalls/