Cisco Confirms Attackers Are Actively Crashing ASA and FTD VPN Devices
Cisco has issued a fresh security advisory confirming that a serious flaw in its Secure Firewall ASA and Firepower Threat Defense (FTD) software is under active attack. The vulnerability allows an unauthenticated remote attacker to send crafted traffic to a device's VPN components and force it to crash, cutting off connectivity until it reboots or is manually restored.
Because ASA and FTD appliances often sit at the edge of corporate networks handling remote-access and site-to-site VPN traffic, a successful attack can disrupt business operations for every user relying on that connection. Cisco has not detailed exactly who is behind the exploitation attempts or how widespread they are, but the company's decision to flag real-world exploitation alongside the fix signals that this isn't just a theoretical risk.
Cisco is urging administrators running affected ASA and FTD versions to apply the available software updates immediately. As with previous ASA-related incidents, these edge devices have repeatedly been a favorite target for both opportunistic attackers and more sophisticated groups looking for a foothold into enterprise networks.