Cisco reports more than 35 vulnerabilities in firewall products

Cisco's ASA, Firepower and Secure Firewall Management Center have security vulnerabilities, some of which are critical. More than 35 updates are now available.

Save to Pocket listen Print view
Stylized image: A stack of burning Cisco appliances

Vulnerabilities threaten Cisco devices.

(Image: Bild erstellt mit KI in Bing Designer durch heise online / dmk)

3 min. read

There are some critical security gaps in Cisco firewall products. The manufacturer has now published numerous security notifications with associated software updates to correct the problems.

On Cisco's overview page for vulnerability reports, the developers posted 37 reports on Thursday night, only one of which updates a report from November 2023. Three of the security reports deal with vulnerabilities classified as critical risk, eleven with high risk, 21 vulnerabilities classified as medium threat level and one further report is of an informative nature without risk assessment.

The vulnerabilities affect Cisco's Firepower Threat Defense software, the Secure Firewall Management Center software and Cisco's Adaptive Security Appliances. IT managers should check whether they are using vulnerable products and apply available updates or use available workarounds if necessary.

The list of security messages classified as critical or high-risk:

The other vulnerability reports can be found in Cisco's overview.

Last weekend, it became known that attackers had gained access to Cisco data in a DevHub portal. Cisco has confirmed the attack and also that data has been leaked. However, Cisco's own systems are not said to have been directly affected.

(dmk)

Don't miss any news – follow us on Facebook, LinkedIn or Mastodon.

This article was originally published in German. It was translated with technical assistance and editorially reviewed before publication.