Impact
A logic error in the ACL Object Group Search (OGS) implementation of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software allows an unauthenticated, remote attacker to send traffic that should be blocked through the device. If successful, the attacker bypasses configured access controls and can reach devices in protected networks.
Affected Systems
The vulnerability affects Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software. No specific version information is provided in the advisory, so the impact applies to all releases prior to the published fix.
Risk and Exploitability
The CVSS score is 5.3, indicating a medium severity vulnerability. The EPSS score is less than 1%, implying a very low likelihood of exploitation at present. The vulnerability is not listed in CISA's KEV catalog. The attack vector appears to be remote, unauthenticated traffic directed through the firewall. The exploitation path requires the attacker to craft traffic that matches a blocked ACL rule but is processed by the faulty OGS logic to be allowed.
OpenCVE Enrichment