Skip to content

CISA Issues Emergency Directive for Vulnerabilities Affecting Cisco Devices

Recent vulnerabilities allow for remote code execution and privilege escalation.

Moving train superimposed with colorful binary pattern
Image compiled from Pixabay

A new emergency directive from CISA outlines mandated action to protect against zero-day vulnerabilities targeting Cisco devices.

“CISA is aware of an ongoing exploitation campaign by an advanced threat actor targeting Cisco Adaptive Security Appliances (ASA). The campaign is widespread and involves exploiting zero-day vulnerabilities to gain unauthenticated remote code execution on ASAs, as well as manipulating read-only memory (ROM) to persist through reboot and system upgrade,” the directive states.

The following vulnerabilities pose an “unacceptable risk” to federal information systems and must be addressed immediately:

Required steps – as detailed in the directive – include:

  • Accounting for all Cisco ASA and Firepower devices
  • Collecting forensics and assessing compromise via CISA-provided procedures and tools
  • Disconnecting end-of-support devices
  • Upgrading devices to remain in use

Read more at CISA.

Add ADMIN IT Infrastructure & Operations on Google