Slashdot Mirror


Cisco ASA Firewall Has a Wormable Problem — And a Million Installs (csoonline.com)

itwbennett writes: Cisco has published an advisory for a vulnerability with a CVSS (Common Vulnerability Scoring System) score of 10 that was discovered by researchers from Exodus Intelligence. According to the advisory, 'a vulnerability in the Internet Key Exchange (IKE) version 1 (v1) and IKE version 2 (v2) code of Cisco ASA Software could allow an unauthenticated, remote attacker to cause a reload of the affected system or to remotely execute code.' As CSO's Dave Lewis points out, 'the part of this that is most pressing is that Cisco claims that there are over a million of these deployed.'
And attackers have not been sitting on their thumbs.

4 of 78 comments (clear)

  1. Great! Now if only they would make upgrades easier by Anonymous Coward · · Score: 5, Informative

    In our branch office we have two ASA 5505 devices (the small blue boxes), with software versions dating back a couple of years because of 'no support contract with Cisco'.
    I have been trying, literally for days, to get a quote for a sw upgrade license, to no avail.

    You can not buy it online.
    You can not but it from Cisco, you have to go through a reseller.
    Resellers simply do not answer any requests for a quote for a single license, because it is not worth their time...

    I am at the point where I'm ready to buy new boxes, just because they come with the latest sw version. The price point is not astronomical.

    How on earth are customers supposed to be secure if they make it so hard to keep up with patches ???

  2. Re:Great! Now if only they would make upgrades eas by hawguy · · Score: 5, Informative

    In our branch office we have two ASA 5505 devices (the small blue boxes), with software versions dating back a couple of years because of 'no support contract with Cisco'.
    I have been trying, literally for days, to get a quote for a sw upgrade license, to no avail.

    You can not buy it online.
    You can not but it from Cisco, you have to go through a reseller.
    Resellers simply do not answer any requests for a quote for a single license, because it is not worth their time...

    I am at the point where I'm ready to buy new boxes, just because they come with the latest sw version. The price point is not astronomical.

    How on earth are customers supposed to be secure if they make it so hard to keep up with patches ???

    Replace your ASA's with pfSense boxes (buy them pre-made or make your own). Lifetime updates for free, no support contract needed, and no hidden backdoors, the code is open for inspection. You can buy support if you want it.

  3. Re:Great! Now if only they would make upgrades eas by dills · · Score: 5, Informative

    To be fair, Cisco is handing out free upgrades with this vulnerability. Call TAC, give them your serial number, and a few hours later you should have a download link in your email.

  4. Update is 'free', even without maintenance by Anonymous Coward · · Score: 4, Informative

    From Cisco's site it appears they will supply the update but you have to contact support. Haven't tried it yet but might be worth contacting them...

    https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20160210-asa-ike

    Customers Without Service Contracts

    Customers who purchase directly from Cisco but do not hold a Cisco service contract and customers who make purchases through third-party vendors but are unsuccessful in obtaining fixed software through their point of sale should obtain upgrades by contacting the Cisco Technical Assistance Center (TAC):
    http://www.cisco.com/en/US/support/tsd_cisco_worldwide_contacts.html

    Customers should have the product serial number available and be prepared to provide the URL of this advisory as evidence of entitlement to a free upgrade.