Impact
The vulnerability arises from incorrect calculation logic in Cisco Secure Adaptive Security Appliance (ASA), Threat Defense (FTD), and Management Center (FMC) software. Faulty computations that influence security decision points can result in the firewall misclassifying traffic or applying rules incorrectly, thereby potentially allowing traffic to bypass intended enforcement. The weakness is identified as CWE‑682, a logical error in software computation, and the CVSS score of 8.1 reflects the high impact on network security and integrity.
Affected Systems
Affected vendors and products include Cisco Secure Firewall Adaptive Security Appliance (ASA) Software, Cisco Secure Firewall Threat Defense (FTD) Software, and Cisco Secure Firewall Management Center (FMC). No specific firmware or software version information is provided in the CVE data, so the affected releases remain unspecified.
Risk and Exploitability
The CVSS score of 8.1 indicates high severity, while the EPSS score of less than 1% suggests a very low exploitation probability at the time of analysis. The vulnerability is not listed in the CISA KEV catalog. Based on the nature of the flaw, the likely attack vector involves exploiting an incorrectly evaluated policy or rule within the firewall’s decision engine, which could be triggered remotely by crafting traffic that forces the flawed computation to alter policy evaluation.
OpenCVE Enrichment