Impact
The vulnerability involves a failure of protection mechanisms (CWE-693) that can allow an attacker to bypass or weaken security controls in Cisco Secure Firewall products. It is rated severely high with a CVSS score of 9.6, indicating a high potential impact on confidentiality, integrity, or availability if exploited. The description does not detail specific consequences, but the nature of the weakness suggests that an attacker could gain unauthorized actions or read protected configuration data.
Affected Systems
Affected products are Cisco Secure Firewall Adaptive Security Appliance (ASA) Software, Cisco Secure Firewall Threat Defense (FTD) Software, and Cisco Secure Firewall Management Center (FMC). No specific version ranges are listed in the advisory, so all versions of these products that have not incorporated the hardening release could be vulnerable.
Risk and Exploitability
Risk assessment shows a CVSS score of 9.6 and an EPSS score of less than 1 %, indicating a low likelihood of exploitation at present, and the vulnerability is not listed in the CISA KEV catalog. Without an explicit attack vector, it is inferred that an attacker would need to be able to reach the device through administrative interfaces or exposed services. The exploitability is therefore likely limited to privileged or remote users that have network access to the firewall devices, and the vendor recommends applying the hardening release to mitigate the risk.
OpenCVE Enrichment