Impact
The vulnerability is a logic flaw in the ACL Object Group Search implementation of Cisco Secure Firewall Adaptive Security Appliance (ASA) and Cisco Secure Firewall Threat Defense (FTD). It results in improper access control (CWE‑284) whereby an attacker can send traffic that should be blocked, enabling them to bypass configured ACLs and reach devices in protected networks. The primary impact is the ability to bypass organizational access controls, potentially exposing or sensitive internal resources.
Affected Systems
The affected systems are Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software. No specific versions are listed in the advisory, so all deployments using these products could be vulnerable until the patch is applied.
Risk and Exploitability
The CVSS score of 5.8 indicates a moderate severity, and the EPSS score of less than 1 % suggests a low probability of exploitation in the wild. The vulnerability is not cataloged in the CISA KEV list. The exploit requires an unauthenticated remote attacker to craft traffic that is intended to be denied by the ACL but is instead allowed due to the logic error in populating group access control policies with Object Group Search. If exploited, the attacker would have compromised network perimeter defenses and could potentially gain lateral movement into the protected network.
OpenCVE Enrichment