Cisco disclosed more than two dozen vulnerabilities in its IOS and IOS XE network automation software and one critical bug in the web interface of its Adaptive Security Appliance (ASA).

Of the IOS and IOS XE flaws, Cisco deemed 12 high vulnerability and 16 medium.

The critical vulnerability is a particularly nasty one that affects Cisco’s ASA software and its Firepower Threat Defense software running on several of the vendor’s network security products including data center, industrial, and virtual security appliances, as well as cloud and next-gen firewalls.

The vendor “strongly recommends” that customers upgrade to a fixed ASA software release because “there are continued attempts to exploit [this bug] in the wild.”

This vulnerability could allow an unauthenticated, remote attacker to cause an affected device to reload unexpectedly, resulting in a denial of service. It could also cause the ASA to not reload, but still allow the attacker to view sensitive system information without authentication.

Lack of proper input validation of the HTTP URL cause this flaw, and an attacker could exploit it by proper input validation of the HTTP.

Cisco released software updates to patch this vulnerability, and it says there are no workarounds.

High-Impact Bugs

While none of the other security flaws ranked “critical,” one of the high-impact bugs that affects Cisco 800 Series Industrial Integrated Services Routers and 1000 Series Connected Grid Routers received a 9.9 out of 10 Common Vulnerability Scoring System (CVSS) score. This score would usually correspond to a critical label. But because it’s localized within the Guest OS instance, Cisco classified it high impact. “Under no circumstance could an exploitation allow the attacker to gain administrative access to the IOS software running on an affected device.”

An attacker, however, could exploit this vulnerability by authenticating to the Guest OS using the low-privileged-user credentials. This could then allow the attacker to gain unauthorized access to the Guest OS as a root user.

However, the Cisco Product Security Incident Response Team says it’s not aware of any attacks or malicious use of this vulnerability.

The vendor issued software upgrades to fix this and all of the other vulnerabilities disclosed.