CIO Influence
CIO Influence News Networking Security

Positive Technologies Identifies Vulnerabilities in Cisco Systems Firewalls, Cisco Implements Fixes

Positive Technologies Identifies Vulnerabilities in Cisco Systems Firewalls, Cisco Implements Fixes
Successful exploits could cause denial of service and block access to corporate networks

Cisco Systems Inc. has conveyed its thanks to Positive Technologies cybersecurity expert Nikita Abramov for identifying two vulnerabilities in Adaptive Security Appliance and Firepower Threat Defense of Cisco hardware firewalls. The two vulnerabilities are very common—Positive Technologies believes they potentially affect hundreds of thousands of devices.

Recommended ITech News: Code Dx and Secure Code Warrior Join Forces to Launch “Project Better Code”

“The main danger is that attackers can send a specially crafted package to cause denial of service of the firewall—the  device will reload, and users will be denied access to a company’s internal network (for example, via VPN), which can significantly affect business processes amidst the pandemic,” Mr. Abramov noted.  “The number of devices exposed to these vulnerabilities is similar to the number of devices affected by CVE-2020-3259, which affected the Cisco ASA firewall and was found in 220,000 devices.”

 The attack does not require any additional rights, access or authorization. All attackers have to do is send a special request using a special path. Mr.  Abramov reports that any organization using vulnerable devices to offer employees access to internal resources via VPN is in danger.

Recommended ITech News: MandM Direct Manages Models at Scale with Dataiku

Both vulnerabilities, officially CVE-2021-1445 and CVE-2021-1504, have a CVSS 3.1 score of 8.6, reflecting a high degree of danger. These are logical errors that often appear due to developers’ carelessness or insufficient code testing during development.

To eliminate vulnerabilities, users are advised to follow the recommendations specified in the official Cisco notice. To detect attempts to exploit vulnerabilities in the Cisco firewall, network traffic analysis systems (NTA/NDR) can be used, for example PT Network Attack Discovery. If an attack is successful, signs of penetration can be detected with SIEM solutions such as MaxPatrol SIEM, which help identify suspicious behavior, register an incident, and prevent intruders from moving laterally within the corporate network in a timely manner.

Recommended ITech News: Involta Acquires SecureData 365 Data Center in Canton, Ohio

Related posts

Ermetic Releases Open Source Tool to Automatically Troubleshoot AccessDenied Errors on AWS

IBM Closes Acquisition of Turbonomic to Deliver Comprehensive AIOps Capabilities for Hybrid Cloud

CIO Influence News Desk

Sysdig CSPM Remediates Security Issues in Seconds

CIO Influence News Desk