Who is affected
This vulnerability affects Cisco Secure Firewall Adaptive Security Appliance (ASA) and Secure Firewall Threat Defense (FTD) devices. An unauthenticated remote attacker can trigger a heap inspection flaw that causes the device to reload unexpectedly, creating a denial of service condition. The record does not specify affected software versions or deployment configurations.
How to check whether this touches you
- Inventory all Cisco Secure Firewall ASA and FTD appliances in your organisation, including virtual instances.
- Confirm whether each device is reachable from the internet or from untrusted networks; devices isolated to trusted internal segments carry lower risk.
- Check the running software version on each device via the CLI (
show version) or management interface; version alone does not confirm mitigation status, as Cisco may have backported fixes into earlier releases. - Review Cisco's security advisory for this CVE to determine which versions contain the patch and whether your deployment falls within the affected range.
What to do
- If you cannot patch immediately, prioritise devices that face the internet or untrusted networks for additional monitoring and network segmentation review.
- Consult Cisco's published advisory to identify the patched software version(s) and plan a maintenance window for deployment; coordinate with your change management process.
- Apply the vendor patch in accordance with Cisco's instructions and CISA's BOD 26-04 guidance on patching timelines for internet-facing assets.
- If mitigations are unavailable for your device model or software version, evaluate discontinuation of the product or enhanced network controls as alternatives.
- Enable and review device reload logs and syslog output during and after patching to confirm successful remediation and detect any unexpected reloads.
If you find you were exposed
Exploitation typically precedes public disclosure; check device logs and syslog archives for unexpected reloads or crashes in the weeks before the advisory date. Correlate reload timestamps with external traffic patterns and any suspicious connection attempts. Confirm log retention policies cover at least 90 days; if logs have been overwritten, document the gap and use this as input to your log retention review.