cisco-sa-asaftd-info-disclose-9eJtycMB: Cisco Adaptive Security Appliance Software and Firepower Threat Defense Software Web Services Information Disclosure Vulnerability
A vulnerability in the web services interface of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to retrieve memory contents on an affected device, which could lead to the disclosure of
Credit
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 9.13.1.10Fixed in 9.12.3.9Fixed in 9.10.1.40Fixed in 9.9.2.67Fixed in 9.8.4.20Fixed in 9.6.4.41 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 6.5.0.5 (future release)Cisco_FTD_Hotfix_H-6.5.0.5-2.sh.REL.tar and laterCisco_FTD_SSP_FP1K_Hotfix_H-6.5.0.5-2.sh.REL.tar and laterCisco_FTD_SSP_FP2K_Hotfix_H-6.5.0.5-2.sh.REL.tar and laterCisco_FTD_SSP_Hotfix_H-6.5.0.5-2.sh.REL.tar and laterFixed in 6.3.0.6 (future release)Cisco_FTD_Hotfix_AO-6.3.0.6-2.sh.REL.tarCisco_FTD_SSP_FP2K_Hotfix_ AO-6.3.0.6-2.sh.REL.tarCisco_FTD_SSP_Hotfix_ AO-6.3.0.6-2.sh.REL.tarFixed in 6.2.3.16 (June 2020)Cisco_FTD_Hotfix_DT-6.2.3.16-3.sh.REL.tarCisco_FTD_SSP_FP2K_Hotfix_DT-6.2.3.16-3.sh.REL.tarCisco_FTD_SSP_Hotfix_DT-6.2.3.16-3.sh.REL.tar
Event History
Frequently Asked Questions
What is the vulnerability ID for this Cisco ASA Software and Firepower Threat Defense (FTD) Software vulnerability?
The vulnerability ID for this Cisco ASA Software and Firepower Threat Defense (FTD) Software vulnerability is cisco-sa-asaftd-info-disclose-9eJtycMB.
What is the severity level of vulnerability cisco-sa-asaftd-info-disclose-9eJtycMB?
The severity level of vulnerability cisco-sa-asaftd-info-disclose-9eJtycMB is high.
What is the affected software?
The affected software is Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software.
What can an attacker do with this vulnerability?
An unauthenticated, remote attacker can retrieve memory contents on an affected device, leading to the disclosure of confidential information.
Is there a fix available for this vulnerability?
Yes, there are specific versions available for Cisco ASA Software and FTD Software that address this vulnerability.