Impact
The vulnerability arises from improper handling of exceptional conditions in the Cisco Secure Firewall components. According to the description, the software hardening release addresses multiple internally discovered weaknesses related to the Common Weakness Enumeration pillar CWE-703. The flaw can cause the system to behave unpredictably when unexpected events occur, potentially leading to a denial of service or service instability.
Affected Systems
The affected systems include Cisco Secure Firewall Adaptive Security Appliance (ASA) Software, Cisco Secure Firewall Management Center (FMC), and Cisco Secure Firewall Threat Defense (FTD) Software. No specific version ranges are listed; any instance of these products running prior to the hardening release is potentially impacted.
Risk and Exploitability
The CVSS score of 9.9 indicates a critical severity. The EPSS score is less than 1%, indicating a low likelihood of exploitation, and the vulnerability is not listed in CISA KEV. Nevertheless, the high severity requires prompt action. While the description does not specify an exact exploit path, the vulnerability likely requires the ability to trigger exceptional conditions through management interfaces or normal operational states, making privileged access or remote management a probable attack vector.
OpenCVE Enrichment