Impact
The vulnerability arises from incorrect comparison conditions, classified under CWE-697, which can enable an attacker to bypass intended controls. While the exact downstream impact is not specified in the advisory, such logic flaws typically allow an adversary to gain unintended privileges or access. The description indicates that the flaw was internally discovered and addressed in a hardening release, suggesting that the vulnerability could have allowed unauthorized actions if exploited.
Affected Systems
Affected systems include Cisco Secure Firewall Adaptive Security Appliance (ASA) Software, Cisco Secure Firewall Threat Defense (FTD) Software, and Cisco Secure Firewall Management Center (FMC). No specific version information was provided, so administrators should assume that all current supported releases may contain the flaw until a patched version is identified.
Risk and Exploitability
The CVSS score of 8.8 classifies this issue as high severity. The EPSS score of less than 1% indicates a low probability of exploitation. This vulnerability is not listed in the CISA KEV catalog, suggesting it has not yet been targeted by known exploitation campaigns. Nonetheless, the logic bypass presents a clear attack vector for adversaries who can target the firmware or management interfaces, potentially leading to unauthorized configuration changes or elevated privileges.
OpenCVE Enrichment