A bug discovered this week in Cisco’s Firepower Threat Defense (FTD) and Adaptive Security Appliance (ASA) firewalls could lead to denial-of -ervice (DoS) attacks, warned Positive Technologies threat researchers.
The high-severity vulnerability (CVE-2021-34704) doesn’t require elevated privileges or special access to exploit, according to Positive Technologies analyst Nikita Abramov. An attacker simply has to form a request in which one of the parts is a different size than expected by the device.
The vulnerability is the result of an improper input validation when parsing HTTPS requests, Cisco reports. If exploited, the bug could allow the attacker to cause the device to reload, resulting in a DoS condition, the vendor added.
This could have a severe impact on business operations, noted Abramov. “If attackers disrupt the operation of Cisco ASA and Cisco FTD, a company will be left without a firewall and remote access,” he wrote in a research note. “If the attack is successful, remote employees or partners will not be able to access the internal network of the organization and access from outside will be restricted. At the same time, firewall failure will reduce the protection of the company.”
Cisco has already patched the bug in the latest release of its ASA and FTD firmware.
Positive Technologies also recommends customers with affected devices to take advantage of security information and event management (SIEM) services to detect and mitigate breaches.
Cisco Battles Security VulnerabilitiesToday’s bug is the latest to impact Cisco firewall customers. In August, the vendor patched a vulnerability in its Firepower Devices Manager (FDM) and On-Box software which enabled researchers to gain control of the company’s Firepower next-generation firewalls.
The vulnerability, discovered by Abramov and threat researcher Mikhail Klyuchnikov, garnered a common vulnerability scoring system score of 6.3 in severity.
The bug took advantage of a flaw in Cisco’s FDM On-Box representational state transfer (REST) API, which enables attackers to run arbitrary code on the operating system of an affected device.
“To exploit this vulnerability, all attackers need to do is to obtain credentials of a user with low privileges and send a specially crafted HTTP request,” Abramov wrote. “From a technical standpoint, the vulnerability is caused by insufficient user input validation for some REST API commands.”
Comments