Impact
CVSS score of 8.4 indicates a high‑severity vulnerability, yet the Advisory does not describe a specific impact or exploitation method. The weakness is classified as a coding‑standard violation (CWE‑710), which typically reflects improper implementation of requirements such as segregation of duties, data masking, or protection against accidental disclosure. Because no concrete effect is specified, the precise consequence for confidentiality, integrity, or availability remains uncertain.
Affected Systems
The vulnerability affects Cisco Secure Firewall Adaptive Security Appliance (ASA) Software, Cisco Secure Firewall Threat Defense (FTD) Software, and Cisco Secure Firewall Management Center (FMC) when running firmware versions that predate the hardening release. The hardening release contains fixes that address the coding‑standards issues. No specific version numbers are listed in the advisory, so any deployment of the pre‑release software is considered at risk until the hardening update is applied.
Risk and Exploitability
The CVSS score of 8.4 classifies this issue as high severity. EPSS score of less than 1 % indicates a very low likelihood of exploitation at the time of this analysis, and the vulnerability is not catalogued in the CISA Known Exploited Vulnerabilities database. The Advisory does not disclose an explicit attack vector; it is inferred that exploitation would require privileged access to the device or a successful compromise of the internal code, which could lead to unauthorized configuration changes or other system tampering.
OpenCVE Enrichment