These critical Cisco bugs need patching immediately

(Image credit: Future)

Cisco has released updates to address a dozen high-severity flaws in its Adaptive Security Appliance (ASA) software and its Firepower Threat Defense (FTD) software.

If left unpatched, these vulnerabilities could allow an attacker to cause a memory leak, disclose information, view and delete sensitive information, bypass authentication or create a denial of service (DoS) condition on an affected device.

The most severe of these flaws is a path-traversal vulnerability in Cisco's ASA and FTD software tracked as CVE-2020-3187. This vulnerability in WebVPN, which can be exploited even by a low-skilled hacker, could allow an unauthorized external attacker to perform DoS attacks on Cisco ASA devices by simply deleting files from the system and this could possibly lead to VPN connections in Cisco ASA being disabled.

In a blog post, web application penetration tester at Positive Technologies, Mikhail Klyuchnikov explained how VPN blocking could disrupt an organization's business processes, saying:

"VPN blocking may disrupt numerous business processes. For example, this can affect connection between branch offices in a distributed network, disrupt email, ERP, and other critical systems. Another problem is that internal resources may become unavailable to remote workers. This is especially dangerous now that many employees are working remotely due to the coronavirus outbreak."

Cisco ASA and FTD software flaws

Cisco also fixed seven additional high-severity flaws in its ASA and FTD software including one dealing with the Kerberos authentication feature of ASA.

Kerberos is a common authentication protocol for on-premise authentication which is used in many ASA interfaces. If exploited, the flaw tracked as CVE-2020-3125 could enabled an unauthenticated, remote attacker to impersonate the Kerberos key distribution center (KDC) as a result of insufficient identity verification of the KDC.

Cisco also released patches for four flaws in its FTD software including a flaw tracked as CVE-2020-3189 in the VPN System Logging functionality of the software. According to the company's advisory, this flaw is due to “the system memory not being properly freed for a VPN System Logging event generated when a VPN session is created or deleted”. An attacker could exploit this flaw by repeatedly creating or deleting a VPN tunnel connection which leaks a small amount of system memory for each logging event.

In total, Cisco issued 34 patches to address 12 high severity and 22 medium severity flaws. It is highly recommended that users patch their software immediately to avoid falling victim to any potential attacks.

Via ThreatPost

Anthony Spadafora

After working with the TechRadar Pro team for the last several years, Anthony is now the security and networking editor at Tom’s Guide where he covers everything from data breaches and ransomware gangs to the best way to cover your whole home or business with Wi-Fi. When not writing, you can find him tinkering with PCs and game consoles, managing cables and upgrading his smart home. 

Latest in Software & Services
TinEye website
I like this reverse image search service the most
A person in a wheelchair working at a computer.
Here’s a free way to find long lost relatives and friends
A white woman with long brown hair in a ponytail looks down at her computer in a distressed manner. She is holding her forehead with one hand and a credit card with the other
This people search finder covers all the bases, but it's not perfect
That's Them home page
Is That's Them worth it? My honest review
woman listening to computer
AWS vs Azure: choosing the right platform to maximize your company's investment
A person at a desktop computer working on spreadsheet tables.
Trello vs Jira: which project management solution is best for you?
Latest in News
Zendesk Relate 2025
Zendesk Relate 2025 - everything you need to know as the event unfolds
Disney Plus logo with popcorn
You can finally tell Disney+ to stop bugging you about that terrible Marvel show you regret starting
Google Gemini AI
Gemini can now see your screen and judge your tabs
Girl wearing Meta Quest 3 headset interacting with a jungle playset
Latest Meta Quest 3 software beta teases a major design overhaul and VR screen sharing – and I need these updates now
Philips Hue
Philips Hue might be working on a video doorbell, and according to a new report, we just got our first look at it
Microsoft
"Another pair of eyes" - Microsoft launches all-new Security Copilot Agents to give security teams the upper hand