Impact
The vulnerability is an improper access control flaw that can allow an attacker to gain elevated privileges on Cisco Secure Firewall devices. With the flaw, a privileged operation could be executed beyond the authorized boundary, potentially enabling local or remote code execution and unauthorized configuration changes. The weakness is classified as CWE‑284, indicating that valid users can perform actions intended only for higher‑privileged accounts.
Affected Systems
The affected products are Cisco Secure Firewall Adaptive Security Appliance (ASA) Software, Cisco Secure Firewall Threat Defense (FTD) Software, and Cisco Secure Firewall Management Center (FMC) Software. No specific version ranges are listed in the advisory, so all versions that have not received the hardening release may be vulnerable.
Risk and Exploitability
The CVSS score of 9.9 shows a high severity and the potential for complete system compromise. The EPSS score of <1% indicates that the exploitation probability is low at the time of analysis, and the vulnerability is not listed in the CISA KEV catalog. Based on the nature of the flaw and the description, the likely attack vector is remote network, where an attacker could send crafted traffic to privileged interfaces or exploit administrative endpoints to bypass access controls. The fixed hardening release mitigates the flaw and should be applied promptly to avoid exploitation.
OpenCVE Enrichment