Monday, February 5, 2018

UPDATE: Cisco ASA Remote Code Execution and Denial of Service Vulnerability

Bad news folks, Cisco said that they have "identified additional attack vectors" and we need to patch our ASA's again.

https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20180129-asa1

edit:

REcon Brussels Presentation Slides: https://www.nccgroup.trust/globalassets/newsroom/uk/events/2018/02/reconbrx2018-robin-hood-vs-cisco-asa.pdf

Fixed Versions:

Major Release Fixed Release ============================================== 8.x1 Affected; migrate to 9.1.7.23 9.01 Affected; migrate to 9.1.7.23 9.1 9.1.7.23 9.2 9.2.4.27 9.31 Affected; migrate to 9.4.4.16 9.4 9.4.4.16 9.51 Affected; migrate to 9.6.4.3 9.6 9.6.4.3 9.7 9.7.1.21 9.8 9.8.2.20 9.9 9.9.1.2 


No comments:

Post a Comment