Subscribe to the Premier Computers blog

Get new posts on security, compliance, and business in your inbox.

← Back to all articles
Company News

Another Cisco Firewall Flaw Is Being Used to Crash Devices, and CISA Wants You to Notice

A newly exploited vulnerability in Cisco's ASA and FTD software can knock VPN and firewall appliances offline, and it's a reminder that the boxes guarding your network edge need just as much care as the systems they protect.

Cisco’s ASA (Adaptive Security Appliance) and FTD (Firepower Threat Defense) products are the kind of gear most people never think about, until they stop working. These are firewalls and VPN gateways that sit at the edge of a network, deciding what traffic gets in and out. So when a flaw in that software is actively being exploited, it’s a big deal, even if the attack itself “just” causes a crash.

That’s exactly what’s happening here. Researchers and Cisco itself have confirmed a vulnerability in ASA and FTD that attackers are using in the wild to trigger a denial-of-service (DoS) condition. In plain terms, that means someone can send the device something it doesn’t know how to handle, and the device falls over. No data theft, no ransomware payload, just a device that stops doing its job.

CISA has added this bug (along with a couple of others) to its Known Exploited Vulnerabilities catalog, which is basically the government’s way of saying “this isn’t theoretical, patch it now.” Federal agencies are required to act on these within a set timeline, but the catalog is a useful signal for everyone else too, especially if your organization runs Cisco security appliances at scale.

Why does a crash matter so much? Because these devices are often the last line of defense for VPN access and network segmentation. If a hospital’s remote clinicians can’t get through a downed VPN gateway, that’s a patient care problem, not just an IT ticket. If a bank’s edge firewall drops offline during trading hours, that’s an availability and compliance headache. And if a government agency’s remote access infrastructure goes dark, that can ripple into continuity of operations. Denial-of-service attacks get less attention than breaches, but for sectors that depend on uptime, they can be just as costly.

There’s also a pattern worth noting. Cisco’s edge security products have had a rough few years of disclosures, and attackers clearly know these appliances are high-value targets sitting on the internet’s front porch. That makes patch management for perimeter devices a recurring, not one-time, job.

The practical takeaway for security teams in finance, healthcare, and government is simple: check whether you’re running affected ASA or FTD versions, apply Cisco’s fix, and treat perimeter hardware with the same urgency you’d give a critical server.

Questions Worth Sitting With

  • Should denial-of-service bugs get the same urgency as data-theft vulnerabilities, or is that overkill for most organizations?
  • Does the repeated pattern of Cisco edge device flaws change how much trust organizations should place in a single vendor’s perimeter hardware?
  • How much should CISA’s Known Exploited Vulnerabilities catalog influence private-sector patching decisions outside of federal mandates?
  • Are organizations doing enough to plan for what happens when a VPN gateway or firewall simply goes offline, rather than assuming breaches are the only real risk?
  • Should critical infrastructure sectors be required to disclose when their edge devices go down due to exploited vulnerabilities?